Untrusted search path in auth_query connection handler in PgBouncer before 1.25.1 allows an unauthenticated attacker to execute arbitrary SQL during authentication via a malicious search_path parameter in the StartupMessage.
2025-12-03T19:15:55.227
2025-12-05T23:48:41.397
Analyzed
f86ef6dc-4d3a-42ad-8f28-e6d5547a5007
CVSSv3.1: 7.5 (HIGH)