Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Jason Tsang

#31612of 53,633
8.1Total CVSS
Vulnerabilities · 1
PT-2025-48983
8.1
2025-12-03
Pgbouncer · Pgbouncer · CVE-2025-12819
**Name of the Vulnerable Software and Affected Versions** PgBouncer versions prior to 1.25.1 **Description** A flaw exists in PgBouncer’s authentication process due to an untrusted search path within the `auth query` connection handler. This allows an unauthenticated attacker to execute arbitrary SQL code during authentication by manipulating the `search path` parameter in the StartupMessage. The `search path` parameter is used to define the schema search order for database objects. **Recommendations** Upgrade to PgBouncer version 1.25.1 or later.