{"id":"CVE-2026-6668","title":"Integer overflow in the packet buffer growth logic in PgBouncer through 1.25.2 allows an unauthenticated remote attacker to cause a denial of service","summary":"Integer overflow in the packet buffer growth logic in PgBouncer through 1.25.2 allows an unauthenticated remote attacker to cause a denial of service. Sufficiently large input makes the buffer size computation overflow, leaving the growt…","severity":"high","cvss":7.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","cwe":["CWE-190","CWE-835"],"product":"PgBouncer","affected":["PgBouncer <= 1.25.2"],"published":"2026-09-23","updated":"2026-09-23","sourceUpdated":"2026-09-23T19:40:10.000","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-6668","references":[{"url":"https://www.pgbouncer.org/changelog.html","label":"f86ef6dc-4d3a-42ad-8f28-e6d5547a5007"}],"tags":["nvd","cve.org"],"ssvc":{"exploitation":"none","automatable":"yes","technicalImpact":"partial","timestamp":"2026-09-23T16:33:22.320321Z"},"ingestedAt":"2026-09-23T16:27:22.664Z","slug":"CVE-2026-6668","body":"## Overview\n\nInteger overflow in the packet buffer growth logic in PgBouncer through 1.25.2 allows an unauthenticated remote attacker to cause a denial of service. Sufficiently large input makes the buffer size computation overflow, leaving the growth loop unable to terminate. Because PgBouncer serves all clients from a single process, this saturates a CPU core and stalls every pooled connection until the process is killed. Both unauthenticated and authenticated code paths can reach the overflow.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"twilight","depthScore":41,"depthScoreParts":{"impact":41.3,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}