CVE-2025-12819: Untrusted search path in auth_query connection in PgBouncer
Untrusted search path in authquery connection handler in PgBouncer before 1.25.1 allows an unauthenticated attacker to execute arbitrary SQL during authentication via a malicious searchpath parameter in the StartupMessage.
Other sources
Untrusted search path in authquery connection in PgBouncer
— Microsoft
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-12819?
CVE-2025-12819 is classified as a high severity vulnerability due to the impact it can have on database security.
How do I fix CVE-2025-12819?
To fix CVE-2025-12819, upgrade PgBouncer to version 1.25.0 or later.
Who is affected by CVE-2025-12819?
Any user running PgBouncer versions prior to 1.25.0 is affected by CVE-2025-12819.
What type of vulnerability is CVE-2025-12819?
CVE-2025-12819 is an untrusted search path vulnerability that allows arbitrary SQL execution.
Can CVE-2025-12819 be exploited remotely?
Yes, CVE-2025-12819 can be exploited by unauthenticated attackers remotely during the authentication process.