| Bug | bookworm | trixie | forky | sid | Description |
|---|
| CVE-2026-19888 | vulnerable | vulnerable | vulnerable | fixed | Missing validation of a mandatory attribute in the SCRAM client-final- ... |
| CVE-2026-6669 | vulnerable | vulnerable | vulnerable | fixed | Missing upper bound on the key derivation iteration count accepted dur ... |
| CVE-2026-6668 | vulnerable | vulnerable | vulnerable | fixed | Integer overflow in the packet buffer growth logic in PgBouncer throug ... |
| CVE-2026-6667 | vulnerable (no DSA) | fixed | fixed | fixed | PgBouncer before 1.25.2 did not perform an appropriate authorization c ... |
| CVE-2026-6666 | vulnerable (no DSA) | fixed | fixed | fixed | A possible null pointer reference in PgBouncer before 1.25.2 could lea ... |
| CVE-2026-6665 | vulnerable (no DSA) | fixed | fixed | fixed | The SCRAM code in PgBouncer before 1.25.2 did not check the return val ... |
| CVE-2026-6664 | vulnerable (no DSA) | fixed | fixed | fixed | An integer overflow in network packet parsing code in PgBouncer before ... |