PgBouncer 1.26.0 released - Fixes three CVEs

PgBouncer 1.26.0 is now available, addressing three denial-of-service vulnerabilities including unauthenticated client crashes and buffer issues. The release also tracks search path and default transaction read only settings by default, introduces pool idle timeout, permits per user query wait timeouts, adds meson build support, and removes deprecated online restart functionality.

The maintainers of the PostgreSQL connection pooler have issued version 1.26.0 to resolve three specific security flaws. These vulnerabilities allow unauthenticated clients or malicious servers to trigger denial-of-service attacks through distinct mechanisms. The updates include fixes for crashes, infinite loops, and unbounded processing during the login sequence. The new release also introduces several configuration changes and removes older functional elements. Users of this lightweight PostgreSQL tool are protected against remote attacks that previously required no valid credentials. The patch addresses integer overflow issues in packet buffer logic and unbound SCRAM iteration counts. Security researchers can also leverage the new tracking defaults for search paths and transaction read-only states. These improvements enhance the tool's robustness against both external threats and internal performance abuse. The source text does not specify the exact severity ratings assigned to the listed CVEs. It also fails to detail any potential data loss risks beyond the noted denial-of-service impacts. No information is provided regarding the timeline for when affected users should deploy this specific update. The description avoids claiming that other components of the database ecosystem share these particular vulnerabilities.