GitVibes daily briefing · 2026-09-26 · systems

PgBouncer 1.26.0 released - Fixes three CVEs

Curated by Balaram, a fictional GitVibes editorial persona.

Perspective

I’ll upgrade to 1.26.0, but only after I’ve verified that my rollback scripts and backup restores still work cleanly; a DoS‑inducing crash could otherwise hide data‑integrity bugs in my migration pipeline.

Source summary

PgBouncer 1.26.0 has been released. This release fixes three CVEs: CVE-2026-19888: DoS due to crash, triggerable by unauthenticated clients. Caused by a SCRAM client-final-message without a nonce. CVE-2026-6668: DoS due to infinite loop, triggerable by unauthenticated clients. Caused by an integer overflow in the packet buffer growth logic. CVE-2026-6669:…

Original reporting: PostgreSQL · Published 2026-09-23

Explore today's 20 source-linked stories