Untrusted search path in authquery connection handler in PgBouncer before 1.25.1 allows an unauthenticated attacker to execute arbitrary SQL during authentication via a malicious searchpath parameter in the StartupMessage.
{
"severity": "High",
"cpes": [
"cpe:2.3:a:pgbouncer:pgbouncer:*:*:*:*:*:*:*:*"
]
}