CyberRota Analysis
AI-GeneratedThe vulnerability in PgBouncer allows unauthenticated remote attackers to crash the service by sending a malformed SCRAM client-final-message, which leads to a NULL pointer dereference due to missing validation of a mandatory attribute. This results in the termination of all pooled connections, impacting service availability. Organizations using PgBouncer, particularly those relying on it for connection pooling in PostgreSQL environments, should prioritize addressing this issue to maintain service stability and security.
Original NVD Description
Missing validation of a mandatory attribute in the SCRAM client-final-message parser in PgBouncer through 1.25.2 allows an unauthenticated remote attacker to crash the process. A malformed message can make the parser report success while leaving a required value unset, which is then dereferenced as a NULL pointer. The crash occurs before any credential is verified, so no valid account is required. Because PgBouncer serves all clients from a single process, this terminates every pooled connection.