PgBouncer是PgBouncer社区的一个 PostgreSql 的开源轻量级连接池。 PgBouncer 1.25.2之前版本存在输入验证错误漏洞,该漏洞源于网络数据包解析代码中的整数溢出绕过了边界检查,可能导致未经身份验证的远程攻击者通过特制的SCRAM身份验证数据包使PgBouncer崩溃。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | PgBouncer | 0 ~ 1.25.2 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-6665 | 8.1 HIGH | PgBouncer buffer overflow in SCRAM |
| CVE-2026-8193 | 6.3 MEDIUM | Akaunting Invoice PDF Rendering dompdf.php server-side request forgery |
| CVE-2026-6666 | 5.9 MEDIUM | PgBouncer crash in kill_pool_logins_server_error |
| CVE-2026-8186 | 5.3 MEDIUM | Open5GS NF client.c ogs_sbi_client_send_via_scp_or_sepp out-of-bounds |
| CVE-2026-8187 | 5.3 MEDIUM | Open5GS UPF gtp-path.c _gtpv1_u_recv_cb resource consumption |
| CVE-2026-8195 | 4.3 MEDIUM | JeecgBoot SVG File CommonController.java cross site scripting |
| CVE-2026-8194 | 4.3 MEDIUM | osTicket Dispatcher class.dispatcher.php cross-site request forgery |
| CVE-2026-6667 | 4.3 MEDIUM | PgBouncer missing authorization check in KILL_CLIENT admin command |
| CVE-2026-8196 | 3.7 LOW | JeecgBoot mLogin Endpoint LoginController.java authorization |
No comments yet