CVE-2026-6668

Summary

Integer overflow in the packet buffer growth logic in PgBouncer through 1.25.2 allows an unauthenticated remote attacker to cause a denial of service. Sufficiently large input makes the buffer size computation overflow, leaving the growth loop unable to terminate. Because PgBouncer serves all clients from a single process, this saturates a CPU core and stalls every pooled connection until the process is killed. Both unauthenticated and authenticated code paths can reach the overflow.

Affected Software

VendorProductVersion RangeStatus
n/aPgBouncer0 <= 1.25.2affected

Weaknesses

  • CWE-190: Integer Overflow or Wraparound
  • CWE-835: Loop with Unreachable Exit Condition ('Infinite Loop')

Workarounds

Set max_packet_size well below 1073741824 so that no single packet can grow a packet buffer past the overflow threshold

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: yes
    • Technical Impact: partial

References