Microsoft Security Response Center guidance
Vendor revision: Aug 12, 2026CBL-Mariner Releases
Vendor-listed releases
- 1.24.1-1
Vulnerability intelligence
CVE-2025-2291 and is rated Critical severity with a CVSS score of 9.8. It is not in the current CISA KEV record we collected. That does not prove exploitation has not occurred.
CBL-Mariner Releases
Vendor-listed releases
Password can be used past expiry in PgBouncer due to auth_query not taking into account Postgres its VALID UNTIL value, which allows an attacker to log in with an already expired password
Source: NVD