CVE-2026-6664Disclosure(pgbouncer / pgbouncer)

MEDIUMCVSS 7.5 · HIGH

Exploitation ongoing with high activity in latest observed window (2 mentions)

Immediate actions

  • Patch pgbouncer pgbouncer systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

An integer overflow in network packet parsing code in PgBouncer before 1.25.2 bypasses a boundary check and can lead to a crash. An unauthenticated remote attacker can crash PgBouncer with a malformed SCRAM authentication packet.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-190

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • pgbouncer

Threat summary

  • Active exploitation appears in 1 classified signals
  • Patch or workaround signal is available
  • 6 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 5 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • Peaked 2d ago at 2 mentions (2026-05-10); latest day: 2
  • 6 total mentions across 4 days

Affected systems

Vendors
Products
pgbouncer

Deep dive

Activity timeline6 mentions / 4d
01122Mentions · 2026-05-09: 1Mentions · 2026-05-10: 2Mentions · 2026-05-11: 1Mentions · 2026-05-20: 2Active Exploitation · 2026-05-20: 1Patch / Workaround · 2026-05-10: 1Patch / Workaround · 2026-05-11: 1Technical Details · 2026-05-09: 1Technical Details · 2026-05-10: 2Technical Details · 2026-05-20: 205-0905-1005-1105-20
Signal classification4 categories
Disclosure
233.3%
Patch
233.3%
General
116.7%
Active Exploitation
116.7%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-05-091
Disclosure1
2026-05-102
General1Patch1
2026-05-111
Patch1
2026-05-202
Active Exploitation1Disclosure1
Full discourse6 posts
  • Euler Taveira@eulerto
    Patch

    PgBouncer 1.25.2 released - Human touch with fresh twist in title race full of uncertainties (including CVE-2026-6664, CVE-2026-6665, Fix CVE-2026-6666, CVE-2026-6667) https://www.pgbouncer.org/changelog.html#pgbouncer-125x

    Post summary

    PgBouncer 1.25.2 release notes announce fixes for CVE-2026-6664, 6665, 6666, and 6667, indicating a patch was applied, but no additional technical details or exploitation evidence are presented.

    0005095
    442 followersView on X
  • CCB Alert@CCBalert
    Active Exploitation

    Warning: High Integer Overflow in #PgBouncer. #CVE-2026-6664 CVSS: 7.5 It's actively exploited by unauthenticated network-based attackers who can cause system crash. #Patch #Patch #Patch

    Post summary

    CVE-2026-6664 describes a high integer overflow in PgBouncer that is being actively exploited by unauthenticated attackers, leading to system crashes; no patch details are provided.

    01000219
    7.2K followersView on X
  • ThreatCluster@threatcluster
    Disclosure

    BREAKING: Critical PgBouncer bug CVE-2026-6664 lets unauthenticated remote attackers crash services in all versions before 1.25.2 via malformed SCRAM auth packets. https://threatcluster.io/cluster/critical-integer-overflow-vulnerability-in-pgbouncer-cve-202-59f90e53

    Post summary

    Announcement of a critical vulnerability in PgBouncer (CVE-2026-6664) that permits unauthenticated remote attackers to crash the service via malformed SCRAM authentication packets.

    0000078
    274 followersView on X
  • Upwind Security MDR@UpwindMDR
    Patch

    🚨 High severity vulnerabilities disclosed in PgBouncer SCRAM authentication handling • CVE-2026-6664 - integer overflow in packet parsing can let an unauthenticated attacker crash PgBouncer using malformed SCRAM authentication packets • CVE-2026-6665 - malicious backend responses can trigger a stack overflow during SCRAM message handling Affected versions: < 1.25.2 👉 Users running exposed PgBouncer instances may want to review and update their deployments to version 1.25.2

    Post summary

    The tweet highlights two high‑severity bugs in PgBouncer’s SCRAM handling and urges users to patch to version 1.25.2.

    0000092
    176 followersView on X
  • CVEarity@CVEarity
    General

    ⚡ New CVE Alert: CVE-2026-6664 📊 Severity: 7.5 🚨 Risk Level: High 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-6664 #CVE-2026-6664 #CVE #High #CyberSecurity #InfoSec https://t.co/vshicmd6X1

    Post summary

    The tweet announces CVE-2026-6664 with a severity score and general impact, but lacks technical, exploit, patch, or active exploitation details.

    0000052
    157 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-6664 Integer Overflow in PgBouncer Before 1.25.2 Causes Remote Denial of Service https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-6664

    Post summary

    The text announces CVE-2026-6664, describing an integer overflow in PgBouncer that leads to remote denial of service but provides no exploit code, patch information, or evidence of active attacks.

    0000048
    4.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Apppgbouncerpgbouncer---

Explore more