CVE-2025-12819
03.12.2025, 19:15
Untrusted search path in auth_query connection handler in PgBouncer before 1.25.1 allows an unauthenticated attacker to execute arbitrary SQL during authentication via a malicious search_path parameter in the StartupMessage.Enginsight
| Vendor | Product | Version |
|---|---|---|
| pgbouncer | pgbouncer | 𝑥 < 1.25.1 |
𝑥
= Vulnerable software versions
Ubuntu Releases
Common Weakness Enumeration