{"id":"CVE-2021-3935","details":"When PgBouncer is configured to use \"cert\" authentication, a man-in-the-middle attacker can inject arbitrary SQL queries when a connection is first established, despite the use of TLS certificate verification and encryption. This flaw affects PgBouncer versions prior to 1.16.1.","aliases":["BIT-pgbouncer-2021-3935"],"modified":"2026-03-13T05:07:36.722862Z","published":"2021-11-22T16:15:07.440Z","references":[{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TNPCV3KRDI5PLLLKADFVIOHACQJLZMLI/"},{"type":"WEB","url":"https://lists.debian.org/debian-lts-announce/2025/05/msg00032.html"},{"type":"ADVISORY","url":"http://www.pgbouncer.org/changelog.html#pgbouncer-116x"},{"type":"ADVISORY","url":"https://lists.debian.org/debian-lts-announce/2022/02/msg00016.html"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2021251"}],"affected":[{"database_specific":{"unresolved_ranges":[{"events":[{"introduced":"0"},{"fixed":"1.16.1"}]},{"events":[{"introduced":"0"},{"last_affected":"7.0"}]},{"events":[{"introduced":"0"},{"last_affected":"35"}]},{"events":[{"introduced":"0"},{"last_affected":"9.0"}]}],"source":"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2021-3935.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}