StackRadar

CVE-2025-12819

High

Advisory

Published 3 Dec 2025In the index since 8 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.004
30th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
8
of 17,781 indexed, latest versions
Container images
8
deployed by those charts
Fix available
1 of 2
affected packages

Untrusted search path in auth_query connection in PgBouncer

Carried by container images the latest versions of 8 of 17,781 indexed charts deploy, on 8 images.

Affected packageAffected versionsFixed inImages
pgbouncerdeb1.8.1-1build1, 1.17.0-3.pgdg22.04+1, 1.17.0-4.pgdg22.04+1, 1.18.0-1.pgdg22.04+1+3 moreno fix listed7
pgbouncerbitnami1.23.1-11.25.11
OSV records
BIT-pgbouncer-2025-12819UBUNTU-CVE-2025-12819

Charts affected

8 by stars
ChartLatestAffected imagesRadar Score
pgbouncerkubernetes-helm-chart-pgbouncer1.0.151 of 1See more

pgbouncer kubernetes-helm-chart-pgbouncer 1.0.15

1 of the 1 container images this version deploys carry CVE-2025-12819.

Container imageDigestPackageFixed in
cradlepoint/pgbouncer:1.0.18f5720b0cd03
pgbouncer@1.8.1-1build1
no fix listed

Open the chart page →

5,802
routehub-client-hubroutehub-helm1.0.01 of 3See more

routehub-client-hub routehub-helm 1.0.0

1 of the 3 container images this version deploys carry CVE-2025-12819.

Container imageDigestPackageFixed in
timescale/timescaledb-ha:pg16d7db8f1085a3
pgbouncer@1.25.2-1.pgdg22.04+1
no fix listed

Open the chart page →

12,930
astrotrekastria0.0.21 of 4See more

astrotrek astria 0.0.2

1 of the 4 container images this version deploys carry CVE-2025-12819.

Container imageDigestPackageFixed in
timescale/timescaledb-ha:pg15-latesta8e3322e1cf9
pgbouncer@1.18.0-1.pgdg22.04+1
no fix listed

Open the chart page →

32,501
kube-acp-stackcloudentity2.28.01 of 7See more

kube-acp-stack cloudentity 2.28.0

1 of the 7 container images this version deploys carry CVE-2025-12819.

Container imageDigestPackageFixed in
timescale/timescaledb-ha:pg17.2-ts2.18.2e8d0a9cc3db5
pgbouncer@1.23.1-1.pgdg22.04+1
no fix listed

Open the chart page →

20,900
codecovdoubanVerified publisher0.2.41 of 8See more

codecov douban 0.2.4

1 of the 8 container images this version deploys carry CVE-2025-12819.

Container imageDigestPackageFixed in
timescale/timescaledb-ha:pg14.6-ts2.9.1-p1cdb9ae118899
pgbouncer@1.17.0-4.pgdg22.04+1
no fix listed

Open the chart page →

24,917
drogue-cloud-examplesdrogue-iotVerified publisher0.7.111 of 6See more

drogue-cloud-examples drogue-iot 0.7.11

1 of the 6 container images this version deploys carry CVE-2025-12819.

Container imageDigestPackageFixed in
timescale/timescaledb-ha:pg14-ts2.6-latested719c0cd19d
pgbouncer@1.17.0-3.pgdg22.04+1
no fix listed

Open the chart page →

30,699
pgbouncerglassflowVerified publisher0.1.01 of 1See more

pgbouncer glassflow 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-12819.

Container imageDigestPackageFixed in
bitnamilegacy/pgbouncer:1.23.192356da09704
pgbouncer@1.23.1-1
1.25.1

Open the chart page →

3,246
twenty-crmvictorlane0.0.11 of 3See more

twenty-crm victorlane 0.0.1

1 of the 3 container images this version deploys carry CVE-2025-12819.

Container imageDigestPackageFixed in
twentycrm/twenty-postgres-spilo:latest2f78405a78be
pgbouncer@1.22.0-1.pgdg22.04+1
no fix listed

Open the chart page →

13,459

Container images carrying it

8 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
bitnamilegacy/pgbouncer:1.23.192356da09704
pgbouncer@1.23.1-1
1.25.1
1
cradlepoint/pgbouncer:1.0.18f5720b0cd03
pgbouncer@1.8.1-1build1
no fix listed
1
timescale/timescaledb-ha:pg15-latesta8e3322e1cf9
pgbouncer@1.18.0-1.pgdg22.04+1
no fix listed
1
timescale/timescaledb-ha:pg14.6-ts2.9.1-p1cdb9ae118899
pgbouncer@1.17.0-4.pgdg22.04+1
no fix listed
1
timescale/timescaledb-ha:pg16d7db8f1085a3
pgbouncer@1.25.2-1.pgdg22.04+1
no fix listed
1
timescale/timescaledb-ha:pg17.2-ts2.18.2e8d0a9cc3db5
pgbouncer@1.23.1-1.pgdg22.04+1
no fix listed
1
timescale/timescaledb-ha:pg14-ts2.6-latested719c0cd19d
pgbouncer@1.17.0-3.pgdg22.04+1
no fix listed
1
twentycrm/twenty-postgres-spilo:latest2f78405a78be
pgbouncer@1.22.0-1.pgdg22.04+1
no fix listed
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.