pgbouncer is a lightweight connection pooler for PostgreSQL and uses libevent
for low-level socket handling.
Update Information:
Update to 1.25.2.
* Sat May 9 2026 Simone Caronni
[ 1 ] Bug #2419513 - CVE-2025-12819 pgbouncer: Untrusted search path in auth_query connection in PgBouncer [epel-10]
https://bugzilla.redhat.com/show_bug.cgi?id=2419513
[ 2 ] Bug #2419514 - CVE-2025-12819 pgbouncer: Untrusted search path in auth_query connection in PgBouncer [epel-8]
https://bugzilla.redhat.com/show_bug.cgi?id=2419514
[ 3 ] Bug #2419515 - CVE-2025-12819 pgbouncer: Untrusted search path in auth_query connection in PgBouncer [epel-9]
https://bugzilla.redhat.com/show_bug.cgi?id=2419515
[ 4 ] Bug #2419516 - CVE-2025-12819 pgbouncer: Untrusted search path in auth_query connection in PgBouncer [fedora-42]
https://bugzilla.redhat.com/show_bug.cgi?id=2419516
This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-d3d959a176' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label
Get the latest Linux and open source security news straight to your inbox.