Christophe Pettus: Nobody Patches the Pooler

PgBouncer 1.26.0 patches three CVEs, including two that can be triggered without authentication. The update concerns operators using the widely deployed PostgreSQL connection pooler.

Why it matters

Unauthenticated vulnerabilities in a connection pooler can expose database infrastructure, making prompt review of the PgBouncer update important for operators.

Coverage 1 publisher

  1. Planet PostgreSQL

    Christophe Pettus: Nobody Patches the Pooler

Articles stay on their publishers’ sites; each link opens the original.