CVE-2026-6666
A possible null pointer reference in PgBouncer before 1.25.2 could lead to a crash, if a server sends an error response without SQLSTATE field.
- Pgbouncer
- < 1.25.2
- Fix
- Available
- CVSS 3.1
- 7.5 HIGH
- EPSS
- 0.4% (30th percentile)
- Weakness
- CWE-476
- NVD status
- Analyzed
- Published
- 2026-05-09
CVE-2026-6666 at NVD
2 known exploits for CVE-2026-6666
Proof-of-concept code and exploit modules indexed by Sploitus