Missing validation of a mandatory attribute in the SCRAM client-final-message parser in PgBouncer through 1.25.2 allows an unauthenticated remote attacker to crash the process. A malformed message can make the parser report success while leaving a required val
Shenlong is analyzing...
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | PgBouncer | 0 ~ 1.25.2 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-6668 | 7.5 HIGH | Integer overflow causes an infinite loop in packet buffer growth in PgBouncer |
| CVE-2026-79304 | 6.5 MEDIUM | CVE-2026-79304 |
| CVE-2026-79306 | 6.5 MEDIUM | CVE-2026-79306 |
| CVE-2026-6669 | 5.9 MEDIUM | Unbounded SCRAM iteration count causes CPU exhaustion in PgBouncer |
| CVE-2026-95897 | 5.5 MEDIUM | Dask Loader core.py from_npy_stack deserialization |
| CVE-2026-79310 | CVE-2026-79310 | |
| CVE-2025-63564 | CVE-2025-63564 |
No comments yet