Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2025-2291

Password can be used past expiry in PgBouncer due to auth_query not taking into account Postgres its VALID UNTIL value, which allows an attacker to log in with an already expired password
Exploit prediction scoring system (EPSS) score
EPSS Score 0.0
EPSS Ranking 14.8%
CVSS Severity
CVSS v3 Score 8.1
Products affected by CVE-2025-2291


Contact Us

Shodan ® - All rights reserved