Missing upper bound on the key derivation iteration count accepted during SCRAM authentication to a backend server in PgBouncer through 1.25.2 allows a malicious or compromised PostgreSQL backend to cause uncontrolled CPU consumption in PgBouncer. The resultin
Shenlong is analyzing...
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | PgBouncer | 0 ~ 1.25.2 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-19888 | 7.5 HIGH | NULL pointer dereference in SCRAM client-final-message parsing in PgBouncer |
| CVE-2026-6668 | 7.5 HIGH | Integer overflow causes an infinite loop in packet buffer growth in PgBouncer |
| CVE-2026-79304 | 6.5 MEDIUM | CVE-2026-79304 |
| CVE-2026-79306 | 6.5 MEDIUM | CVE-2026-79306 |
| CVE-2026-95897 | 5.5 MEDIUM | Dask Loader core.py from_npy_stack deserialization |
| CVE-2026-79310 | CVE-2026-79310 | |
| CVE-2025-63564 | CVE-2025-63564 |
No comments yet