Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2025-2291


Password can be used past expiry in PgBouncer due to auth_query not taking into account Postgres its VALID UNTIL value, which allows an attacker to log in with an already expired password


Published

2025-04-16T18:16:04.977

Last Modified

2025-12-08T18:32:49.600

Status

Analyzed

Source

f86ef6dc-4d3a-42ad-8f28-e6d5547a5007

Severity

CVSSv3.1: 8.1 (HIGH)

Weaknesses
  • Type: Secondary
    CWE-324

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application pgbouncer pgbouncer < 1.24.1 Yes
Operating System debian debian_linux 11.0 Yes

References