CVE-2026-6668: Integer Overflow or Wraparound in PgBouncer
Integer overflow in the packet buffer growth logic in PgBouncer through 1.25.2 allows an unauthenticated remote attacker to cause a denial of service. Sufficiently large input makes the buffer size computation overflow, leaving the growth loop unable to terminate. Because PgBouncer serves all clients from a single process, this saturates a CPU core and stalls every pooled connection until the process is killed. Both unauthenticated and authenticated code paths can reach the overflow.
AI Analysis
Technical Summary
An integer overflow exists in the packet buffer growth logic of PgBouncer versions up to and including 1.25.2. When processing sufficiently large input, the calculation for buffer size overflows, causing the growth loop to become infinite. Since PgBouncer handles all client connections within a single process, this results in CPU core saturation and stalls all pooled connections, effectively causing a denial of service. Both unauthenticated and authenticated code paths can trigger this overflow.
Potential Impact
The vulnerability allows remote unauthenticated attackers to cause a denial of service by exhausting CPU resources on the PgBouncer server. This stalls all client connections managed by the PgBouncer process until it is manually restarted or killed, disrupting service availability.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, consider limiting exposure of PgBouncer to untrusted networks and monitor for abnormal CPU usage that may indicate exploitation attempts.
CVE-2026-6668: Integer Overflow or Wraparound in PgBouncer
Description
Integer overflow in the packet buffer growth logic in PgBouncer through 1.25.2 allows an unauthenticated remote attacker to cause a denial of service. Sufficiently large input makes the buffer size computation overflow, leaving the growth loop unable to terminate. Because PgBouncer serves all clients from a single process, this saturates a CPU core and stalls every pooled connection until the process is killed. Both unauthenticated and authenticated code paths can reach the overflow.
CVSS v3.1
Score 7.5high
Affected software
PgBouncer
pkg:github/pgbouncer/pgbouncerRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
An integer overflow exists in the packet buffer growth logic of PgBouncer versions up to and including 1.25.2. When processing sufficiently large input, the calculation for buffer size overflows, causing the growth loop to become infinite. Since PgBouncer handles all client connections within a single process, this results in CPU core saturation and stalls all pooled connections, effectively causing a denial of service. Both unauthenticated and authenticated code paths can trigger this overflow.
Potential Impact
The vulnerability allows remote unauthenticated attackers to cause a denial of service by exhausting CPU resources on the PgBouncer server. This stalls all client connections managed by the PgBouncer process until it is manually restarted or killed, disrupting service availability.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, consider limiting exposure of PgBouncer to untrusted networks and monitor for abnormal CPU usage that may indicate exploitation attempts.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- PostgreSQL
- Date Reserved
- 2026-04-20T12:25:46.351Z
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 6ab3ff4ff7a7c541060b303d
Added to database: 09/23/2026, 16:33:19 UTC
Last enriched: 09/23/2026, 16:47:44 UTC
Last updated: 09/24/2026, 01:57:04 UTC
Views: 4
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.