There are 2 open security issues in bookworm.
1 important issue:
- CVE-2025-12819:
Untrusted search path in auth_query connection handler in PgBouncer before 1.25.1 allows an unauthenticated attacker to execute arbitrary SQL during authentication via a malicious search_path parameter in the StartupMessage.
1 issue left for the package maintainer to handle:
- CVE-2025-2291:
(needs triaging)
Password can be used past expiry in PgBouncer due to auth_query not taking into account Postgres its VALID UNTIL value, which allows an attacker to log in with an already expired password
You can find information about how to handle this issue in the security team's documentation.