Marked for autoremoval on 20 December: #1120176high
Version 1.24.1-1 of pgbouncer is marked for autoremoval from testing on Sat 20 Dec 2025. It is affected by #1120176. The removal of pgbouncer will also cause the removal of (transitive) reverse dependencies: python-pgbouncer, storm. You should try to prevent the removal by fixing these RC bugs.
Among the 2 debian patches
available in version 1.25.0-1 of the package,
we noticed the following issues:
2 patches
where the metadata indicates that the patch has not yet been forwarded
upstream. You should either forward the patch upstream or update the
metadata to document its real status.
1 issue left for the package maintainer to handle:
CVE-2025-2291:
(needs triaging)
Password can be used past expiry in PgBouncer due to auth_query not taking into account Postgres its VALID UNTIL value, which allows an attacker to log in with an already expired password