Nobody Patches the Pooler
PgBouncer 1.26.0 came out on September 23 and fixes three CVEs. Two of them can be triggered by anyone who can open a TCP connection to the listener. They need no password and no valid username. If PgBouncer sits anywhere a hostile packet can reach it, upgrade before you finish reading this.