Skip to content
Flaws in PgBouncer Allow Remote Code Execution and Denial of Service

Flaws in PgBouncer Allow Remote Code Execution and Denial of Service

First seen 5 Oct 2026, 11:26 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •October 5, 2026 at 12:27 UTC
  • •Critical vulnerabilities in PgBouncer could lead to arbitrary code execution.
  • •Affected versions include Fedora 43 to 45, with patches available in version 1.26.0.
  • •Users should upgrade immediately to mitigate risks from CVE-2026-6665 and CVE-2026-6666.

Multiple vulnerabilities have been identified in PgBouncer, a lightweight connection pooler for PostgreSQL, affecting Fedora versions 43 to 45. The flaws, tracked as CVE-2026-6664, CVE-2026-6665, and CVE-2026-6666, could allow arbitrary code execution or denial of service via malicious SCRAM authentication packets. The vulnerabilities were disclosed on May 9, 2026, and have a CVSS score of 8.1 for CVE-2026-6665, marking it as a high severity issue. Users are advised to upgrade to PgBouncer version 1.26.0, which contains patches for these vulnerabilities. The updates were made available on September 26, 2026, and users are encouraged to apply them using the 'dnf' update program. Failure to address these vulnerabilities could expose systems to significant risks.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-05-09
CVE-2026-6664, CVE-2026-6665, CVE-2026-6666 published
Multiple vulnerabilities in PgBouncer were disclosed, allowing for remote code execution and denial of service.
Linuxsecurity
2026-09-26
Patch released for PgBouncer
Fedora released version 1.26.0 to address the critical vulnerabilities identified in PgBouncer.
Linuxsecurity

More articles in this cluster (3)

Following this threat?

Track Fedora and CVE-2026-6664 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed

Common questions

Which versions of PgBouncer are affected?
Fedora versions 43 to 45 are affected by the vulnerabilities.
What should I do to protect my systems?
Upgrade to PgBouncer version 1.26.0 immediately to mitigate the vulnerabilities.
Are these vulnerabilities being actively exploited?
No active exploitation has been reported, but the vulnerabilities are critical and should be patched.