CVE-2021-3935
published 2021-11-22CVE-2021-3935: When PgBouncer is configured to use "cert" authentication, a man-in-the-middle attacker can inject arbitrary SQL queries when a connection is first…
high8.1CVSS 3.1
AVNACHPRNUINSUCHIHAH
When PgBouncer is configured to use "cert" authentication, a man-in-the-middle attacker can inject arbitrary SQL queries when a connection is first established, despite the use of TLS certificate verification and encryption. This flaw affects PgBouncer versions prior to 1.16.1.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | pgbouncer | < pgbouncer 1.16.1-1 (bookworm) | pgbouncer 1.16.1-1 (bookworm) |
| fedoraproject | fedora | — | — |
| msrc | cm1_pgbouncer_1.16.1-1_on_cbl_mariner_1.0 | — | — |
| pgbouncer | pgbouncer | < 1.16.1 | 1.16.1 |
| pgbouncer | pgbouncer | — | — |
| pgbouncer | pgbouncer | >= 0 < 1.15.0-1+deb11u1 | 1.15.0-1+deb11u1 |
| pgbouncer | pgbouncer | >= 0 < 1.16.1-1 | 1.16.1-1 |
| pgbouncer | pgbouncer | >= 0 < 1.16.1-1 | 1.16.1-1 |
| pgbouncer | pgbouncer | >= 0 < 1.16.1-1 | 1.16.1-1 |
| redhat | enterprise_linux | — | — |
CVSS provenance
nvdv3.18.1HIGHCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
osv8.1HIGH
GHSA
GHSA-jh4v-gqwq-hfrr: When PgBouncer is configured to use "cert" authentication, a man-in-the-middle attacker can inject arbitrary SQL queries when a connection is first es
ghsa_unreviewed·2022-05-24
CVE-2021-3935 [HIGH] CWE-295 GHSA-jh4v-gqwq-hfrr: When PgBouncer is configured to use "cert" authentication, a man-in-the-middle attacker can inject arbitrary SQL queries when a connection is first es
When PgBouncer is configured to use "cert" authentication, a man-in-the-middle attacker can inject arbitrary SQL queries when a connection is first established, despite the use of TLS certificate verification and encryption. This flaw affects PgBouncer versions prior to 1.16.1.
OSV
CVE-2021-3935: When PgBouncer is configured to use "cert" authentication, a man-in-the-middle attacker can inject arbitrary SQL queries when a connection is first es
osv·2021-11-22·CVSS 8.1
CVE-2021-3935 [HIGH] CVE-2021-3935: When PgBouncer is configured to use "cert" authentication, a man-in-the-middle attacker can inject arbitrary SQL queries when a connection is first es
When PgBouncer is configured to use "cert" authentication, a man-in-the-middle attacker can inject arbitrary SQL queries when a connection is first established, despite the use of TLS certificate verification and encryption. This flaw affects PgBouncer versions prior to 1.16.1.
Microsoft
When PgBouncer is configured to use "cert" authentication a man-in-the-middle attacker can inject arbitrary SQL queries when a connection is first established despite the use of TLS certificate verifi
vendor_msrc·2021-11-09·CVSS 8.1
CVE-2021-3935 [HIGH] CWE-295 When PgBouncer is configured to use "cert" authentication a man-in-the-middle attacker can inject arbitrary SQL queries when a connection is first established despite the use of TLS certificate verifi
When PgBouncer is configured to use "cert" authentication a man-in-the-middle attacker can inject arbitrary SQL queries when a connection is first established despite the use of TLS certificate verification and encryption. This flaw affects PgBouncer versions prior to 1.16.1.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more inf
Debian
CVE-2021-3935: pgbouncer - When PgBouncer is configured to use "cert" authentication, a man-in-the-middle a...
vendor_debian·2021·CVSS 8.1
CVE-2021-3935 [HIGH] CVE-2021-3935: pgbouncer - When PgBouncer is configured to use "cert" authentication, a man-in-the-middle a...
When PgBouncer is configured to use "cert" authentication, a man-in-the-middle attacker can inject arbitrary SQL queries when a connection is first established, despite the use of TLS certificate verification and encryption. This flaw affects PgBouncer versions prior to 1.16.1.
Scope: local
bookworm: resolved (fixed in 1.16.1-1)
bullseye: resolved (fixed in 1.15.0-1+deb11u1)
forky: resolved (fixed in 1.16.1-1)
sid: resolved (fixed in 1.16.1-1)
trixie: resolved (fixed in 1.16.1-1)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://www.pgbouncer.org/changelog.html#pgbouncer-116xhttps://bugzilla.redhat.com/show_bug.cgi?id=2021251https://lists.debian.org/debian-lts-announce/2022/02/msg00016.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TNPCV3KRDI5PLLLKADFVIOHACQJLZMLI/http://www.pgbouncer.org/changelog.html#pgbouncer-116xhttps://bugzilla.redhat.com/show_bug.cgi?id=2021251https://lists.debian.org/debian-lts-announce/2022/02/msg00016.htmlhttps://lists.debian.org/debian-lts-announce/2025/05/msg00032.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TNPCV3KRDI5PLLLKADFVIOHACQJLZMLI/
2021-11-22
Published