EXPOSURES › CVE-2026-6665
CVE-2026-6665
HIGH
DETAIL
SourceNVD · cve
Published2026-05-09
CVSS8.1
Referencehttps://nvd.nist.gov/vuln/detail/CVE-2026-6665 ↗
▸ RECOMMENDED ACTION Patch the affected products and confirm your instances are covered.
PLAYERS IMPLICATED
DESCRIPTION
The SCRAM code in PgBouncer before 1.25.2 did not check the return value of strlcat() correctly when building the contents of the SCRAM client-final-message. A malicious backend that sends a SCRAM server-final-message with a long nonce can trigger a stack overflow.
AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.