---
id: CVE-2026-6669
title: >-
  Missing upper bound on the key derivation iteration count accepted during
  SCRAM authentication to a backend server in PgBouncer through 1.25.2 allows a
  malicious or compromised PostgreSQL backend to cause uncontrolled CPU
  consumption in …
summary: >-
  Missing upper bound on the key derivation iteration count accepted during
  SCRAM authentication to a backend server in PgBouncer through 1.25.2 allows a
  malicious or compromised PostgreSQL backend to cause uncontrolled CPU
  consumption in …
severity: medium
cvss: 5.9
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H'
cwe:
  - CWE-400
  - CWE-835
product: PgBouncer
affected:
  - PgBouncer <= 1.25.2
published: '2026-09-23'
updated: '2026-09-23'
sourceUpdated: '2026-09-23T19:40:10.000'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-6669'
references:
  - url: 'https://www.pgbouncer.org/changelog.html'
    label: f86ef6dc-4d3a-42ad-8f28-e6d5547a5007
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-6669.json
  - url: 'https://access.redhat.com/security/cve/CVE-2026-6669'
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2539546'
  - url: 'https://www.cve.org/CVERecord?id=CVE-2026-6669'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-6669'
tags:
  - nvd
  - cve.org
  - csaf
  - vex
  - red-hat
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-23T16:33:29.069636Z'
ingestedAt: '2026-09-23T16:27:22.663Z'
vendor: Red Hat
---

## Overview

Missing upper bound on the key derivation iteration count accepted during SCRAM authentication to a backend server in PgBouncer through 1.25.2 allows a malicious or compromised PostgreSQL backend to cause uncontrolled CPU consumption in PgBouncer. The resulting key derivation cannot be interrupted in frontend builds such as PgBouncer. Because PgBouncer serves all clients from a single process, one backend can in this way stop it from serving traffic for every other database and client it is pooling, so the failure of a single backend is not contained.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.

## Vendor advisories

- **Red Hat VEX** · Moderate · affected: Red Hat Hardened Images · no fix planned: Red Hat Hardened Images · updated 2026-09-23 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-6669.json)
