Project Subscriptions
No data.
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
| Link | Providers |
|---|---|
| https://www.pgbouncer.org/changelog.html |
|
Wed, 23 Sep 2026 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 23 Sep 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Missing upper bound on the key derivation iteration count accepted during SCRAM authentication to a backend server in PgBouncer through 1.25.2 allows a malicious or compromised PostgreSQL backend to cause uncontrolled CPU consumption in PgBouncer. The resulting key derivation cannot be interrupted in frontend builds such as PgBouncer. Because PgBouncer serves all clients from a single process, one backend can in this way stop it from serving traffic for every other database and client it is pooling, so the failure of a single backend is not contained. | |
| Title | Unbounded SCRAM iteration count causes CPU exhaustion in PgBouncer | |
| Weaknesses | CWE-400 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: PostgreSQL
Published:
Updated: 2026-09-23T16:46:13.708Z
Reserved: 2026-04-20T12:25:47.129Z
Link: CVE-2026-6669
Updated: 2026-09-23T16:36:50.297Z
Status : Received
Published: 2026-09-23T17:17:16.223
Modified: 2026-09-23T17:17:16.223
Link: CVE-2026-6669
No data.
OpenCVE Enrichment
No data.