CVE-2026-6665Disclosure(pgbouncer / pgbouncer)

LOWCVSS 9.8 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch pgbouncer pgbouncer systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

The SCRAM code in PgBouncer before 1.25.2 did not check the return value of strlcat() correctly when building the contents of the SCRAM client-final-message. A malicious backend that sends a SCRAM server-final-message with a long nonce can trigger a stack overflow.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-121

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • pgbouncer

Threat summary

  • Patch or workaround signal is available
  • 5 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 3 classified signals
  • General: 1 classified signal
  • Peaked 1d ago at 3 mentions (2026-05-10); latest day: 1
  • 5 total mentions across 3 days

Affected systems

Vendors
Products
pgbouncer

Deep dive

Activity timeline5 mentions / 3d
01223Mentions · 2026-05-09: 1Mentions · 2026-05-10: 3Mentions · 2026-05-11: 1Patch / Workaround · 2026-05-10: 1Technical Details · 2026-05-10: 205-0905-1005-11
Signal classification3 categories
Disclosure
360.0%
General
120.0%
Patch
120.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-05-091
General1
2026-05-103
Disclosure3
2026-05-111
Patch1
Full discourse5 posts
  • Euler Taveira@eulerto
    Patch

    PgBouncer 1.25.2 released - Human touch with fresh twist in title race full of uncertainties (including CVE-2026-6664, CVE-2026-6665, Fix CVE-2026-6666, CVE-2026-6667) https://www.pgbouncer.org/changelog.html#pgbouncer-125x

    Post summary

    The post announces the release of PgBouncer 1.25.2, noting that it contains fixes for several CVEs, but provides no PoC, exploit details, or active exploitation evidence.

    0005095
    442 followersView on X
  • Upwind Security MDR@UpwindMDR
    Disclosure

    🚨 High severity vulnerabilities disclosed in PgBouncer SCRAM authentication handling • CVE-2026-6664 - integer overflow in packet parsing can let an unauthenticated attacker crash PgBouncer using malformed SCRAM authentication packets • CVE-2026-6665 - malicious backend responses can trigger a stack overflow during SCRAM message handling Affected versions: < 1.25.2 👉 Users running exposed PgBouncer instances may want to review and update their deployments to version 1.25.2

    Post summary

    The post announces high‑severity vulnerabilities in PgBouncer’s SCRAM handling, details the nature of the flaws, and recommends updating to version 1.25.2.

    0000092
    176 followersView on X
  • yerliJHON@yerli_jhon
    Disclosure

    PgBouncer'ın SCRAM authentication'ında buffer overflow var. Veritabanına girmek için şifre kırmaya gerek yok, authentication mekanizmasının kendisi seni içeri alıyor. Kapıya kilidi takan usta kilidi açık bırakmış. CVE-2026-6665 🔓

    Post summary

    The post announces that CVE‑2026‑6665 is a buffer overflow in PgBouncer’s SCRAM authentication, allowing database access without password cracking, but provides no PoC, patch, or evidence of active exploitation.

    0000031
  • CVEarity@CVEarity
    Disclosure

    ⚡ New CVE Alert: CVE-2026-6665 📊 Severity: 8.1 🚨 Risk Level: High 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-6665 #CVE-2026-6665 #CVE #High #CyberSecurity #InfoSec https://t.co/XRtwhwJYEK

    Post summary

    The tweet announces CVE‑2026‑6665, noting its severity score of 8.1 and high risk, but provides no technical exploitation details or mitigation guidance.

    0000061
    157 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-6665 Stack Overflow in PgBouncer SCRAM Authentication Before Version 1.... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-6665 Customizable Vulnerability Alerts: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=4

    Post summary

    The text merely lists the CVE identifier and provides a link to a vulnerability details page, with no further technical or exploitation information.

    0000047
    4.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Apppgbouncerpgbouncer---

Explore more