Vulnerability Description
Password can be used past expiry in PgBouncer due to auth_query not taking into account Postgres its VALID UNTIL value, which allows an attacker to log in with an already expired password
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Pgbouncer | Pgbouncer | < 1.24.1 |
| Debian | Debian Linux | 11.0 |
Related Weaknesses (CWE)
References
- https://www.pgbouncer.org/changelog.html#pgbouncer-124xRelease Notes
- https://lists.debian.org/debian-lts-announce/2025/05/msg00032.htmlMailing ListThird Party Advisory
FAQ
What is CVE-2025-2291?
CVE-2025-2291 is a vulnerability with a CVSS score of 8.1 (HIGH). Password can be used past expiry in PgBouncer due to auth_query not taking into account Postgres its VALID UNTIL value, which allows an attacker to log in with an already expired password
How severe is CVE-2025-2291?
CVE-2025-2291 has been rated HIGH with a CVSS base score of 8.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-2291?
Check the references section above for vendor advisories and patch information. Affected products include: Pgbouncer Pgbouncer, Debian Debian Linux.