CVE-2025-2291
Password can be used past expiry in PgBouncer due to auth_query not taking into account Postgres its VALID UNTIL value, which allows an attacker to log in with an already expired password
Scoring
- Severity
- HIGH
- CVSS base score
- 8.1
- CVSS vector
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS probability
- 0.35%
- CWE
- CWE-324
- Published
- 2025-04-16
- Last modified
- 2026-03-12
Affected products
- n/a PgBouncer
Weakness type
Related vulnerabilities
- CVE-2026-39923 — Flarum < 1.8.16 Password Reset Token Expiry Bypass via POST /reset
- CVE-2026-54787 — sigstore-go fails to check signature timestamps against a signing key's validity period
- CVE-2026-52809 — Gogs: Password-reset tokens use account-activation lifetime, ignoring RESET_PASSWORD_CODE_LIVES
- CVE-2025-33012 — IBM Db2 improper account lockout
- CVE-2025-48813 — Virtual Secure Mode Spoofing Vulnerability
- CVE-2023-5342 — Shim: expired secure boot certificate
- CVE-2025-31123 — Zitadel Expired JWT Keys Usable for Authorization Grants
- CVE-2024-7318 — Keycloak-core: one time passcode (otp) is valid longer than expiration timeseverity