Alerts

Alerts

Nobody Patches the Pooler

PgBouncer 1.26.0 came out on September 23 and fixes three CVEs. Two of them can be triggered by anyone who can open a TCP connection to the listener. They need no password and no valid username. If PgBouncer sits anywhere a hostile packet can reach it, upgrade before you finish reading this.

Now that you’ve started the upgrade, here