Untrusted search path in auth_query connection handler in PgBouncer before 1.25.1 allows an unauthenticated attacker to execute arbitrary SQL during authentication via a malicious search_path parameter in the StartupMessage.
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://www.pgbouncer.org/changelog.html#pgbouncer-125x |
|
History
Sat, 06 Dec 2025 00:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:pgbouncer:pgbouncer:*:*:*:*:*:*:*:* |
Thu, 04 Dec 2025 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Pgbouncer
Pgbouncer pgbouncer |
|
| Vendors & Products |
Pgbouncer
Pgbouncer pgbouncer |
Wed, 03 Dec 2025 23:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Wed, 03 Dec 2025 22:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Untrusted search path in auth_query connection handler in PgBouncer before 1.25.0 allows an unauthenticated attacker to execute arbitrary SQL during authentication via a malicious search_path parameter in the StartupMessage. | Untrusted search path in auth_query connection handler in PgBouncer before 1.25.1 allows an unauthenticated attacker to execute arbitrary SQL during authentication via a malicious search_path parameter in the StartupMessage. |
| References |
|
Wed, 03 Dec 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 03 Dec 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Untrusted search path in auth_query connection handler in PgBouncer before 1.25.0 allows an unauthenticated attacker to execute arbitrary SQL during authentication via a malicious search_path parameter in the StartupMessage. | |
| Title | Untrusted search path in auth_query connection in PgBouncer | |
| Weaknesses | CWE-426 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: PostgreSQL
Published: 2025-12-03T19:00:09.063Z
Updated: 2025-12-03T22:38:58.388Z
Reserved: 2025-11-06T17:22:32.839Z
Link: CVE-2025-12819
Updated: 2025-12-03T19:11:33.360Z
Status : Analyzed
Published: 2025-12-03T19:15:55.227
Modified: 2025-12-05T23:48:41.397
Link: CVE-2025-12819
No data.