When PgBouncer is configured to use "cert" authentication, a man-in-the-middle attacker can inject arbitrary SQL queries when a connection is first established, despite the use of TLS certificate verification and encryption. This flaw affects PgBouncer versions prior to 1.16.1.
Subscriptions
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-2922-1 | pgbouncer security update |
Debian DLA |
DLA-4180-1 | pgbouncer security update |
EUVD |
EUVD-2021-27149 | When PgBouncer is configured to use "cert" authentication, a man-in-the-middle attacker can inject arbitrary SQL queries when a connection is first established, despite the use of TLS certificate verification and encryption. This flaw affects PgBouncer versions prior to 1.16.1. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Mon, 03 Nov 2025 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Status: PUBLISHED
Assigner: fedora
Published:
Updated: 2025-11-03T19:26:17.293Z
Reserved: 2021-11-08T00:00:00.000Z
Link: CVE-2021-3935
No data.
Status : Modified
Published: 2021-11-22T16:15:07.440
Modified: 2025-11-03T20:15:50.153
Link: CVE-2021-3935
No data.
OpenCVE Enrichment
No data.
Debian DLA
EUVD