PgBouncer Null Pointer Dereference Vulnerability Leading to Crash

Vulnerability

A null pointer dereference vulnerability has been identified in PgBouncer versions prior to 1.25.2. This vulnerability can lead to a crash if a server sends an error response lacking the SQLSTATE field. The issue arises from improper handling of error responses, which can create a scenario where PgBouncer attempts to process a null value, causing a crash.

Impact

Exploitation of this vulnerability can cause PgBouncer to crash, disrupting database connection pooling and potentially leading to downtime for applications relying on the service.

Remediation

Users can upgrade to PgBouncer version 1.25.2 or later to address this vulnerability.

Added: May 9, 2026, 1:18 AM
Updated: May 9, 2026, 1:18 AM

Vulnerability Rating

Custom Algorithm
spread
5.7
impact
2.5
exploitability
7.0
remediation
7.7
relevance
7.5
threat
0.0
urgency
2.9
incentive
4.2

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.