CVE-2025-2291

EUVD-2025-11379
Password can be used past expiry in PgBouncer due to auth_query not taking into account Postgres its VALID UNTIL value, which allows an attacker to log in with an already expired password
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
8.1 HIGH
NETWORK
HIGH
NONE
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 27.54%
Affected Products (NVD)
VendorProductVersion
pgbouncerpgbouncer
𝑥
< 1.24.1
debiandebian_linux
11.0
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
pgbouncer
bookworm
1.18.0-1+deb12u1
fixed
bullseye
vulnerable
bullseye (security)
1.15.0-1+deb11u2
fixed
forky
1.25.2-1
fixed
sid
1.25.2-1
fixed
trixie
1.24.1-1+deb13u2
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
pgbouncer
bionic
needs-triage
focal
needs-triage
jammy
needs-triage
noble
needs-triage
oracular
ignored
plucky
ignored
questing
ignored
resolute
not-affected
xenial
needs-triage
Azure Linux logo
Azure Linux Releases
Azure Package
Release
pgbouncer
Azure Linux 3.0
0:1.24.1-1.azl3
fixed
CBL-Mariner 2.0
0:1.24.1-1.cm2
fixed