CVE-2026-6669
Last modified
CVE-2026-6669 is a medium-severity vulnerability rated 5.9/10 on the CVSS scale. Missing upper bound on the key derivation iteration count accepted during SCRAM authentication to a backend server in PgBouncer through 1.25.2 allows a malicious or compromised PostgreSQL backend to cause uncontrolled CPU consumption in PgBouncer. The resulting key derivation cannot be interrupted in frontend builds such as PgBouncer.
Description
Missing upper bound on the key derivation iteration count accepted during SCRAM authentication to a backend server in PgBouncer through 1.25.2 allows a malicious or compromised PostgreSQL backend to cause uncontrolled CPU consumption in PgBouncer. The resulting key derivation cannot be interrupted in frontend builds such as PgBouncer. Because PgBouncer serves all clients from a single process, one backend can in this way stop it from serving traffic for every other database and client it is pooling, so the failure of a single backend is not contained.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| — | PgBouncer | <= 1.25.2 |
References
Timeline
- Published
- Last Modified
- Status
- Awaiting Analysis
Frequently Asked Questions
What is CVE-2026-6669?
How severe is CVE-2026-6669?
How do I fix CVE-2026-6669?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-66684Unauthenticated Sensitive Data Exposure in Export Import Men…5.3
- CVE-2026-66685Unauthenticated Sensitive Data Exposure in Featured Video Pl…5.3
- CVE-2026-66686Unauthenticated Cross Site Request Forgery (CSRF) in Plugins…6.5
- CVE-2026-66687Customer Cross Site Scripting (XSS) in WpBookingly <= 1.3.2 …6.5
- CVE-2026-66688Contributor Cross Site Scripting (XSS) in Ultimate Addons fo…6.5
- CVE-2026-66689Unauthenticated Broken Access Control in Anti Spam and list …6.3
- CVE-2026-66690Unauthenticated Cross Site Scripting (XSS) in GiveWP <= 4.16…7.1
- CVE-2026-66691Unauthenticated Broken Access Control in Nokri <= 1.6.6 vers…9.8
- CVE-2026-66692Customer Insecure Direct Object References (IDOR) in Colissi…4.3
- CVE-2026-66693Subscriber Broken Access Control in Motors <= 1.4.113 versio…6.5
- CVE-2026-66694Unauthenticated Cross Site Scripting (XSS) in Thrive Archite…7.1
- CVE-2026-66695Unauthenticated Path Traversal in W3 Total Cache <= 2.10.2 v…6.5
Are you affected by CVE-2026-6669?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
