Количество 7
Количество 7
BDU:2026-06728
Уязвимость функции strlcat() программного обеспечения для пула соединения в PostgreSQL PgBouncer, позволяющая нарушителю выполнить произвольный код или вызвать отказ в обслуживании
ROS-20260714-73-0050
Уязвимость pgbouncer
CVE-2026-6665
The SCRAM code in PgBouncer before 1.25.2 did not check the return value of strlcat() correctly when building the contents of the SCRAM client-final-message. A malicious backend that sends a SCRAM server-final-message with a long nonce can trigger a stack overflow.
CVE-2026-6665
The SCRAM code in PgBouncer before 1.25.2 did not check the return value of strlcat() correctly when building the contents of the SCRAM client-final-message. A malicious backend that sends a SCRAM server-final-message with a long nonce can trigger a stack overflow.
CVE-2026-6665
PgBouncer buffer overflow in SCRAM
CVE-2026-6665
The SCRAM code in PgBouncer before 1.25.2 did not check the return val ...
GHSA-mhmx-mjv6-w337
The SCRAM code in PgBouncer before 1.25.2 did not check the return value of strlcat() correctly when building the contents of the SCRAM client-final-message. A malicious backend that sends a SCRAM server-final-message with a long nonce can trigger a stack overflow.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
BDU:2026-06728 Уязвимость функции strlcat() программного обеспечения для пула соединения в PostgreSQL PgBouncer, позволяющая нарушителю выполнить произвольный код или вызвать отказ в обслуживании | CVSS3: 8.1 | 0% Низкий | 3 месяца назад | |
ROS-20260714-73-0050 Уязвимость pgbouncer | CVSS3: 8.1 | 0% Низкий | 18 дней назад | |
CVE-2026-6665 The SCRAM code in PgBouncer before 1.25.2 did not check the return value of strlcat() correctly when building the contents of the SCRAM client-final-message. A malicious backend that sends a SCRAM server-final-message with a long nonce can trigger a stack overflow. | CVSS3: 8.1 | 0% Низкий | 3 месяца назад | |
CVE-2026-6665 The SCRAM code in PgBouncer before 1.25.2 did not check the return value of strlcat() correctly when building the contents of the SCRAM client-final-message. A malicious backend that sends a SCRAM server-final-message with a long nonce can trigger a stack overflow. | CVSS3: 8.1 | 0% Низкий | 3 месяца назад | |
CVE-2026-6665 PgBouncer buffer overflow in SCRAM | CVSS3: 8.1 | 0% Низкий | 3 месяца назад | |
CVE-2026-6665 The SCRAM code in PgBouncer before 1.25.2 did not check the return val ... | CVSS3: 8.1 | 0% Низкий | 3 месяца назад | |
GHSA-mhmx-mjv6-w337 The SCRAM code in PgBouncer before 1.25.2 did not check the return value of strlcat() correctly when building the contents of the SCRAM client-final-message. A malicious backend that sends a SCRAM server-final-message with a long nonce can trigger a stack overflow. | CVSS3: 8.1 | 0% Низкий | 3 месяца назад |
Уязвимостей на страницу