Security Advisory

CVE-2026-6664

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-05-09 00:43:42
Last updated 2026-05-11 14:28:49
Assigner PostgreSQL
CVSS score 7.5
State PUBLISHED

Description

An integer overflow in network packet parsing code in PgBouncer before 1.25.2 bypasses a boundary check and can lead to a crash. An unauthenticated remote attacker can crash PgBouncer with a malformed SCRAM authentication packet.