Untrusted search path in auth_query connection handler in PgBouncer before 1.25.1 allows an unauthenticated attacker to execute arbitrary SQL during authentication via a malicious search_path parameter in the StartupMessage.
https://www.pgbouncer.org/changelog.html#pgbouncer-125x
https://lists.debian.org/debian-lts-announce/2025/12/msg00033.html