PgBouncer Released Update Fixing Three Vulnerabilities
The latest software version addresses critical security flaws that allowed unauthenticated users to crash the system.
Updated on Oct. 2, 2026 in Cybersecurity

Live Poll
Do you regularly check for and apply security updates to your critical server software?
Developers released PgBouncer version 1.26.0 to mitigate three newly discovered CVE vulnerabilities. The update resolves security risks that previously allowed unauthorized users to trigger system crashes or hangs.
Why it matters
The software is often excluded from regular security maintenance, making it vital for administrators to apply the latest patches to prevent exploitation. The update specifically addresses flaws in authentication and packet buffer logic.
PgBouncer 1.26.0 introduces a 1,000,000 cap for SCRAM iteration counts and removes the deprecated online restart feature. The update addresses a NULL pointer dereference caused by a missing attribute in the SCRAM handshake.
The players
PgBouncer
PgBouncer is a single-threaded connection pooler for the PostgreSQL database management system.
PostgreSQL
PostgreSQL is a powerful, open-source object-relational database system that utilizes connection poolers to manage traffic.
The details
The release fixes CVE-2026-19888, an authentication bypass and crash vulnerability dating back to version 1.11.0, and CVE-2026-6668, an integer overflow issue in packet buffer growth. Additionally, CVE-2026-6669 addresses denial-of-service risks originating from malicious PostgreSQL servers using high SCRAM iteration counts.
Timeline
August 2019: The authentication bypass vulnerability was introduced in version 1.11.0.
September 23, 2026: PgBouncer version 1.26.0 was officially released.
The Tech Race
The removal of the deprecated online restart feature reflects a shift in architectural security priorities for the tool. This update positions the software to better resist modern denial-of-service threats against database connection infrastructures.
System administrators must prioritize upgrading to version 1.26.0 to secure their database infrastructure against unauthorized access. Developers should note that applications relying on parameter leaks in transaction pooling mode will likely encounter compatibility issues.
The takeaway
Security maintenance for middleware is essential because these tools are frequently overlooked in standard update cycles. Administrators should review their configurations to ensure they align with the new 1,000,000 SCRAM iteration cap.
Further reading
For more information on securing database tools, visit the Cybersecurity section.
Source note: This article includes information reported by Thebuild.
Live Poll
Do you regularly check for and apply security updates to your critical server software?







