PgBouncer是PgBouncer社区的一个 PostgreSql 的开源轻量级连接池。 PgBouncer 1.25.2之前版本存在安全漏洞,该漏洞源于SCRAM代码在构建SCRAM客户端最终消息内容时未正确检查strlcat()的返回值,恶意后端发送包含长随机数的SCRAM服务器最终消息可能触发栈溢出。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | PgBouncer | 0 ~ 1.25.2 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-6664 | 7.5 HIGH | PgBouncer integer overflow in PgBouncer network packet parsing |
| CVE-2026-8193 | 6.3 MEDIUM | Akaunting Invoice PDF Rendering dompdf.php server-side request forgery |
| CVE-2026-6666 | 5.9 MEDIUM | PgBouncer crash in kill_pool_logins_server_error |
| CVE-2026-8186 | 5.3 MEDIUM | Open5GS NF client.c ogs_sbi_client_send_via_scp_or_sepp out-of-bounds |
| CVE-2026-8187 | 5.3 MEDIUM | Open5GS UPF gtp-path.c _gtpv1_u_recv_cb resource consumption |
| CVE-2026-8195 | 4.3 MEDIUM | JeecgBoot SVG File CommonController.java cross site scripting |
| CVE-2026-8194 | 4.3 MEDIUM | osTicket Dispatcher class.dispatcher.php cross-site request forgery |
| CVE-2026-6667 | 4.3 MEDIUM | PgBouncer missing authorization check in KILL_CLIENT admin command |
| CVE-2026-8196 | 3.7 LOW | JeecgBoot mLogin Endpoint LoginController.java authorization |
No comments yet