CVE-2026-19888
7.5 HIGHPublished 2026-09-23 · Updated 2026-09-23
AI analysis for this CVE has not been generated yet. Raw NVD data is shown below.
NVD description
Missing validation of a mandatory attribute in the SCRAM client-final-message parser in PgBouncer through 1.25.2 allows an unauthenticated remote attacker to crash the process. A malformed message can make the parser report success while leaving a required value unset, which is then dereferenced as a NULL pointer. The crash occurs before any credential is verified, so no valid account is required. Because PgBouncer serves all clients from a single process, this terminates every pooled connection.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Weaknesses
CWE-476
All references
Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.
Related CVEs
- MEDIUMCVE-2026-100890
- MEDIUMCVE-2026-100895PoC
- MEDIUMCVE-2026-102623
- UNSCOREDCVE-2026-102723PoC
- UNSCOREDCVE-2026-102724PoC
- MEDIUMCVE-2026-102808PoC
- MEDIUMCVE-2026-18746PoC
- HIGHCVE-2026-42801
Related by shared AI tags and CWE weakness class. Browse the full archive.