OCTOBER 10, 2026
Live Feed
Back to database
Case File

CVE-2026-6668

HIGH · CVSS 7.5 EPSS 0.40%

Source: NVD + CISA KEV + EPSS · Published 2026-09-23 · Last synced 2026-10-10

CyberRota Analysis

AI-Generated

An integer overflow vulnerability in the packet buffer growth logic of PgBouncer versions up to 1.25.2 allows unauthenticated remote attackers to exploit this flaw, leading to a denial of service condition. By sending sufficiently large input, the overflow prevents the buffer growth loop from terminating, causing CPU saturation and stalling all pooled connections until the process is terminated. Organizations using PgBouncer should prioritize patching this vulnerability to mitigate potential service disruptions.

CVE
CVE-2026-6668
Severity
HIGH
CVSS
7.5
EPSS
0.40%

Original NVD Description

Integer overflow in the packet buffer growth logic in PgBouncer through 1.25.2 allows an unauthenticated remote attacker to cause a denial of service. Sufficiently large input makes the buffer size computation overflow, leaving the growth loop unable to terminate. Because PgBouncer serves all clients from a single process, this saturates a CPU core and stalls every pooled connection until the process is killed. Both unauthenticated and authenticated code paths can reach the overflow.