CVE-2026-6664
EUVD-2026-2887609.05.2026, 01:16
An integer overflow in network packet parsing code in PgBouncer before 1.25.2 bypasses a boundary check and can lead to a crash. An unauthenticated remote attacker can crash PgBouncer with a malformed SCRAM authentication packet.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| pgbouncer | pgbouncer | 𝑥 < 1.25.2 |
𝑥
= Vulnerable software versions
Debian Releases