Alerts This Week
Warning Icon 1 631
Alerts This Week
Warning Icon 1 631

Fedora 43 pgbouncer Essential Untrusted Search Path Security Fix Update

fedora
Calendar Grey May 18, 2026
Dist Fedora Esm H88
Critical update for Fedora 43 pgbouncer addresses untrusted search path security issue with CVE-2025-12819.
Update to 1.25.2.

Summary

pgbouncer is a lightweight connection pooler for PostgreSQL and uses libevent

for low-level socket handling.

Update Information:

Update to 1.25.2.

Change Log

* Sat May 9 2026 Simone Caronni - 1.25.2-1 - Update to 1.25.2

References


[ 1 ] Bug #2419513 - CVE-2025-12819 pgbouncer: Untrusted search path in auth_query connection in PgBouncer [epel-10] https://bugzilla.redhat.com/show_bug.cgi?id=2419513 [ 2 ] Bug #2419514 - CVE-2025-12819 pgbouncer: Untrusted search path in auth_query connection in PgBouncer [epel-8] https://bugzilla.redhat.com/show_bug.cgi?id=2419514 [ 3 ] Bug #2419515 - CVE-2025-12819 pgbouncer: Untrusted search path in auth_query connection in PgBouncer [epel-9] https://bugzilla.redhat.com/show_bug.cgi?id=2419515 [ 4 ] Bug #2419516 - CVE-2025-12819 pgbouncer: Untrusted search path in auth_query connection in PgBouncer [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2419516

Update Instructions

This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-fad57ac86d' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

Severity
important
Lowest
Low
Medium
High
Critical

Name: pgbouncer
Product: Fedora 43
Version: 1.25.2
Release: 1.fc43
Summary: Lightweight connection pooler for PostgreSQL

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here