[Git][security-tracker-team/security-tracker][master] Add commit references for pgbouncer issues

Salvatore Bonaccorso (@carnil) carnil at debian.org
Fri Sep 25 13:27:52 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
7150f7db by Salvatore Bonaccorso at 2026-09-25T14:27:12+02:00
Add commit references for pgbouncer issues

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -2153,8 +2153,10 @@ CVE-2026-6718 (IBM Concert 1.0.0 through 3.0.0 is vulnerable to improper access
 	NOT-FOR-US: IBM
 CVE-2026-6669 (Missing upper bound on the key derivation iteration count accepted dur ...)
 	- pgbouncer <unfixed>
+	NOTE: Fixed by: https://github.com/pgbouncer/pgbouncer/commit/0a1d2f8656b508c815f416902bcec38e433a1061 (pgbouncer_1_26_0)
 CVE-2026-6668 (Integer overflow in the packet buffer growth logic in PgBouncer throug ...)
 	- pgbouncer <unfixed>
+	NOTE: Fixed by: https://github.com/pgbouncer/pgbouncer/commit/f2ff5538b0abc262e84dab4e946999dfbd3b0e18 (pgbouncer_1_26_0)
 CVE-2026-6327 (IBM Concert 1.0.0 through 3.0.0 could allow an unauthorized user to in ...)
 	NOT-FOR-US: IBM
 CVE-2026-68492 (An untrusted search path vulnerability in Plesk from 18.0.34 before 18 ...)
@@ -2313,6 +2315,7 @@ CVE-2026-31377 (An Improper Authentication vulnerability in the Apache Doris Fro
 	NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-19888 (Missing validation of a mandatory attribute in the SCRAM client-final- ...)
 	- pgbouncer <unfixed>
+	NOTE: Fixed by: https://github.com/pgbouncer/pgbouncer/commit/35749bc1c4e3c50dd5141071498066d85a011b85 (pgbouncer_1_26_0)
 CVE-2026-19599 (ZohoCorp ManageEngine OpManager MSP versions 12.8.709 and below were v ...)
 	NOT-FOR-US: Zoho
 CVE-2026-19267 (IBM Financial Transaction Manager (FTM) for RedHat OpenShift is vulner ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/7150f7db5ffe9fd11463c9e509697dfa76118e5b

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/7150f7db5ffe9fd11463c9e509697dfa76118e5b
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260925/0ee2c491/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list