Untrusted search path in pgbouncer - CVE-2025-12819
Published: December 6, 2025
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary SQL commands.
The vulnerability exists due to usage of an untrusted search path passed via the search_path parameter in the StartupMessage. A remote non-authenticated attacker can send specially crafted request during authentication and execute arbitrary SQL commands in the database.
Affected software
Fedora
pgbouncer
How to mitigate CVE-2025-12819
pgbouncer - addressed in versions 1.25.2-1.el9, 1.25.2-1.el10_1, 1.25.2-1.el10_2, 1.25.2-1.el10_3, 1.25.2-1.fc42, 1.25.2-1.fc43, 1.25.2-1.fc44