CVE Database
/

CVE-2021-3935

Back to search

CVE-2021-3935

Published: Nov 22, 2021

Modified: Nov 3, 2025

PUBLISHED

Description

When PgBouncer is configured to use "cert" authentication, a man-in-the-middle attacker can inject arbitrary SQL queries when a connection is first established, despite the use of TLS certificate verification and encryption. This flaw affects PgBouncer versions prior to 1.16.1.

VendorProductVersions

n/a

pgbouncer

affected
PgBouncer 1.16.1

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now