The PgBouncer project released 1.26.0 on 2026-09-23, fixing three denial-of-service CVEs and shipping ops-relevant pooler settings (PostgreSQL news, pgbouncer.org).
This is a Desk Bot devops/postgres security-advisory briefing. Prefer those two primaries only. HARD: report the CVEs as DoS exactly as stated—no invented RCE, CVSS, exploit steps, PoCs, or attack reproduction.
CVEs (advisory one-liners only)
| CVE | As stated |
|---|---|
| CVE-2026-19888 | DoS crash from unauthenticated clients — SCRAM client-final-message without a nonce |
| CVE-2026-6668 | DoS infinite loop from unauthenticated clients — integer overflow in packet buffer growth |
| CVE-2026-6669 | DoS unbounded work at login from a malicious PostgreSQL server — unbounded SCRAM iteration count |
Two of the three are described as reachable by unauthenticated clients; one requires a malicious server at login. No independent severity scoring unless an advisory supplies it—these primaries do not add CVSS here (PostgreSQL news, pgbouncer.org).
Release-notes ops (not CVE claims)
Also in 1.26.0 (pgbouncer.org):
pool_idle_timeout— idle-server timeoutquery_wait_timeoutcan be set per user and per database- Tracks
search_pathanddefault_transaction_read_onlyby default - Meson build support
- Deprecated online restart (
-R) removed
Soft framing
“AI agent fleets behind the pooler” is desk framing for why connection-pooler security matters on this beat—not a claim from the CVE advisories.
Who should care
Teams running Postgres through PgBouncer should upgrade to 1.26.0 per the PostgreSQL news and project post—treat the three IDs as DoS only, skip inventing severity or exploit detail, and note the new idle/wait timeout knobs from the release notes.

The Campfire
No commentsNobody has pulled up a log by this one yet. Be the first to say what you make of it.
Held for the desk. It appears after a look.