Debian Package Tracker
Register | Log in
Subscribe

pgbouncer

lightweight connection pooler for PostgreSQL

Choose email to subscribe with

general
  • source: pgbouncer (main)
  • version: 1.25.2-1
  • maintainer: Debian PostgreSQL Maintainers (DMD)
  • uploaders: Peter Eisentraut [DMD] – Christoph Berg [DMD] – Marco Nenciarini [DMD]
  • arch: any
  • std-ver: 4.7.2
  • VCS: Git (Browse, QA)
versions [more versions can be listed by madison] [old versions available from snapshot.debian.org]
[pool directory]
  • o-o-stable: 1.15.0-1
  • o-o-sec: 1.15.0-1+deb11u2
  • oldstable: 1.18.0-1+deb12u1
  • stable: 1.24.1-1+deb13u2
  • testing: 1.25.2-1
  • unstable: 1.25.2-1
versioned links
  • 1.15.0-1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 1.15.0-1+deb11u2: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 1.18.0-1+deb12u1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 1.24.1-1+deb13u2: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 1.25.2-1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
binaries
  • pgbouncer
action needed
Fails to build during reproducibility testing normal
A package building reproducibly enables third parties to verify that the source matches the distributed binaries. It has been identified that this source package produced different results, failed to build or had other issues in a test environment. Please read about how to improve the situation!
Created: 2026-05-19 Last update: 2026-05-22 23:31
4 low-priority security issues in bookworm low

There are 4 open security issues in bookworm.

4 issues left for the package maintainer to handle:
  • CVE-2026-6664: (needs triaging) An integer overflow in network packet parsing code in PgBouncer before 1.25.2 bypasses a boundary check and can lead to a crash. An unauthenticated remote attacker can crash PgBouncer with a malformed SCRAM authentication packet.
  • CVE-2026-6665: (needs triaging) The SCRAM code in PgBouncer before 1.25.2 did not check the return value of strlcat() correctly when building the contents of the SCRAM client-final-message. A malicious backend that sends a SCRAM server-final-message with a long nonce can trigger a stack overflow.
  • CVE-2026-6666: (needs triaging) A possible null pointer reference in PgBouncer before 1.25.2 could lead to a crash, if a server sends an error response without SQLSTATE field.
  • CVE-2026-6667: (needs triaging) PgBouncer before 1.25.2 did not perform an appropriate authorization check for the KILL_CLIENT admin command. All users with access to the administration console (which itself requires authorization) could run this command. It would have been correct to allow only users listed in the admin_users parameter.

You can find information about how to handle these issues in the security team's documentation.

Created: 2026-05-09 Last update: 2026-05-22 22:17
debian/patches: 3 patches to forward upstream low

Among the 3 debian patches available in version 1.25.2-1 of the package, we noticed the following issues:

  • 3 patches where the metadata indicates that the patch has not yet been forwarded upstream. You should either forward the patch upstream or update the metadata to document its real status.
Created: 2023-02-26 Last update: 2026-05-10 07:30
Standards version of the package is outdated. wishlist
The package should be updated to follow the last version of Debian Policy (Standards-Version 4.7.4 instead of 4.7.2).
Created: 2025-12-23 Last update: 2026-05-10 01:46
testing migrations
  • This package will soon be part of the auto-openssl transition. You might want to ensure that your package is ready for it. You can probably find supplementary information in the debian-release archives or in the corresponding release.debian.org bug.
news
[rss feed]
  • [2026-05-17] pgbouncer 1.25.2-1 MIGRATED to testing (Debian testing watch)
  • [2026-05-10] Accepted pgbouncer 1.24.1-1+deb13u2 (source) into proposed-updates (Debian FTP Masters) (signed by: Christoph Berg)
  • [2026-05-09] Accepted pgbouncer 1.25.2-1 (source) into unstable (Christoph Berg)
  • [2026-01-01] Accepted pgbouncer 1.18.0-1+deb12u1 (source) into oldstable-proposed-updates (Debian FTP Masters) (signed by: Andreas Henriksson)
  • [2026-01-01] Accepted pgbouncer 1.24.1-1+deb13u1 (source) into proposed-updates (Debian FTP Masters) (signed by: Andreas Henriksson)
  • [2025-12-27] Accepted pgbouncer 1.15.0-1+deb11u2 (source) into oldoldstable-security (Andreas Henriksson)
  • [2025-12-06] pgbouncer 1.25.1-1 MIGRATED to testing (Debian testing watch)
  • [2025-12-03] Accepted pgbouncer 1.25.1-1 (source) into unstable (Christoph Berg)
  • [2025-11-24] pgbouncer 1.25.0-2 MIGRATED to testing (Debian testing watch)
  • [2025-11-21] Accepted pgbouncer 1.25.0-2 (source) into unstable (Christoph Berg)
  • [2025-11-12] Accepted pgbouncer 1.25.0-1 (source) into unstable (Christoph Berg)
  • [2025-05-26] Accepted pgbouncer 1.15.0-1+deb11u1 (source) into oldstable-security (Andreas Henriksson)
  • [2025-04-27] pgbouncer 1.24.1-1 MIGRATED to testing (Debian testing watch)
  • [2025-04-17] Accepted pgbouncer 1.24.1-1 (source) into unstable (Christoph Berg)
  • [2025-03-26] pgbouncer 1.24.0-3 MIGRATED to testing (Debian testing watch)
  • [2025-03-12] Accepted pgbouncer 1.24.0-3 (source) into unstable (Christoph Berg)
  • [2025-03-12] Accepted pgbouncer 1.24.0-2 (source) into unstable (Christoph Berg)
  • [2024-08-05] pgbouncer 1.23.1-1 MIGRATED to testing (Debian testing watch)
  • [2024-08-03] Accepted pgbouncer 1.23.1-1 (source) into unstable (Bradford D. Boyle) (signed by: Christoph Berg)
  • [2024-07-06] pgbouncer 1.23.0-1 MIGRATED to testing (Debian testing watch)
  • [2024-07-04] Accepted pgbouncer 1.23.0-1 (source) into unstable (Bradford D. Boyle) (signed by: Christoph Berg)
  • [2024-04-26] pgbouncer 1.22.1-1 MIGRATED to testing (Debian testing watch)
  • [2024-04-26] pgbouncer 1.22.1-1 MIGRATED to testing (Debian testing watch)
  • [2024-04-17] Accepted pgbouncer 1.22.1-1 (source) into unstable (Christoph Berg)
  • [2024-02-13] pgbouncer 1.22.0-1 MIGRATED to testing (Debian testing watch)
  • [2024-02-09] Accepted pgbouncer 1.22.0-1 (source) into unstable (Christoph Berg)
  • [2023-10-19] pgbouncer 1.21.0-1 MIGRATED to testing (Debian testing watch)
  • [2023-10-17] Accepted pgbouncer 1.21.0-1 (source) into unstable (Christoph Berg)
  • [2023-09-29] pgbouncer 1.20.1-1 MIGRATED to testing (Debian testing watch)
  • [2023-09-27] Accepted pgbouncer 1.20.1-1 (source) into unstable (Bradford D. Boyle) (signed by: Christoph Berg)
  • 1
  • 2
bugs [bug history graph]
  • all: 1
  • RC: 0
  • I&N: 1
  • M&W: 0
  • F&P: 0
  • patch: 0
links
  • homepage
  • lintian
  • buildd: logs, reproducibility, cross
  • popcon
  • browse source code
  • other distros
  • security tracker
  • screenshots
  • debian patches
  • debci
ubuntu Ubuntu logo [Information about Ubuntu for Debian Developers]
  • version: 1.25.1-1
  • 4 bugs

Debian Package Tracker — Copyright 2013-2025 The Distro Tracker Developers
Report problems to the tracker.debian.org pseudo-package in the Debian BTS.
Documentation — Bugs — Git Repository — Contributing