Files
CVEs-PoC/2025/CVE-2025-2291.md
T
2025-09-29 21:09:30 +02:00

694 B

CVE-2025-2291

Description

Password can be used past expiry in PgBouncer due to auth_query not taking into account Postgres its VALID UNTIL value, which allows an attacker to log in with an already expired password

POC

Reference

No PoCs from references.

Github