Pgbouncer Pgbouncer

Do you want an email whenever new security vulnerabilities are reported in Pgbouncer?

By the Year

In 2024 there have been 0 vulnerabilities in Pgbouncer . Pgbouncer did not have any published security vulnerabilities last year.

Year Vulnerabilities Average Score
2024 0 0.00
2023 0 0.00
2022 0 0.00
2021 2 6.85
2020 0 0.00
2019 0 0.00
2018 0 0.00

It may take a day or so for new Pgbouncer vulnerabilities to show up in the stats or in the list of recent security vulnerabilties. Additionally vulnerabilities may be tagged under a different product or component name.

Recent Pgbouncer Security Vulnerabilities

A flaw was found in c-ares library, where a missing input validation check of host names returned by DNS (Domain Name Servers) can lead to output of wrong hostnames

CVE-2021-3672 5.6 - Medium - November 23, 2021

A flaw was found in c-ares library, where a missing input validation check of host names returned by DNS (Domain Name Servers) can lead to output of wrong hostnames which might potentially lead to Domain Hijacking. The highest threat from this vulnerability is to confidentiality and integrity as well as system availability.

XSS

When PgBouncer is configured to use "cert" authentication, a man-in-the-middle attacker

CVE-2021-3935 8.1 - High - November 22, 2021

When PgBouncer is configured to use "cert" authentication, a man-in-the-middle attacker can inject arbitrary SQL queries when a connection is first established, despite the use of TLS certificate verification and encryption. This flaw affects PgBouncer versions prior to 1.16.1.

Improper Certificate Validation

Stay on top of Security Vulnerabilities

Want an email whenever new vulnerabilities are published for Debian Linux or by Pgbouncer? Click the Watch button to subscribe.

Pgbouncer
Vendor

Pgbouncer
Product

subscribe