PgBouncer 1.26.0 released - Fixes three CVEs

From: PgBouncer via PostgreSQL Announce <announce-noreply(at)postgresql(dot)org>
To: PostgreSQL Announce <pgsql-announce(at)lists(dot)postgresql(dot)org>
Subject: PgBouncer 1.26.0 released - Fixes three CVEs
Date: 2026-09-23 13:44:36
Message-ID: 179017107644.1026195.8202537946345239884@wrigleys.postgresql.org
Views: Whole Thread | Raw Message | Download mbox | Resend email
Thread:
Lists: pgsql-announce

PgBouncer 1.26.0 has been released. This release fixes three CVEs:

1. CVE-2026-19888: DoS due to crash, triggerable by unauthenticated clients. Caused by a SCRAM client-final-message without a nonce.
2. CVE-2026-6668: DoS due to infinite loop, triggerable by unauthenticated clients. Caused by an integer overflow in the packet buffer growth logic.
3. CVE-2026-6669: DoS due to unbounded work during login, triggerable by a malicious PostgreSQL server. Caused by an unbounded SCRAM iteration count.

It also tracks `search_path` and `default_transaction_read_only` by default, adds the `pool_idle_timeout` setting, allows `query_wait_timeout` to be set per user and database, adds meson build support, and removes the deprecated online restart (`-R`) functionality.

See [https://www.pgbouncer.org/2026/09/pgbouncer-1-26-0](https://www.pgbouncer.org/2026/09/pgbouncer-1-26-0) for more information, the detailed changelog, and download links.

PgBouncer is a lightweight connection pooler for PostgreSQL.

Browse pgsql-announce by date

  From Date Subject
Next Message PostgreSQL Global Development Group 2026-09-24 13:00:38 PostgreSQL 19 Beta 4 Released!
Previous Message EMS Software Development via PostgreSQL Announce 2026-09-22 12:10:28 SQL Manager for PostgreSQL 7.0: meet the AI Assistant