Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2025-12764


pgAdmin <= 9.9  is affected by an LDAP injection vulnerability in the LDAP authentication flow that allows an attacker to inject special LDAP characters in the username, causing the DC/LDAP server and the client to process an unusual amount of data DOS.


Published

2025-11-13T13:15:44.910

Last Modified

2025-11-19T21:19:33.810

Status

Analyzed

Source

f86ef6dc-4d3a-42ad-8f28-e6d5547a5007

Severity

CVSSv3.1: 7.5 (HIGH)

Weaknesses
  • Type: Secondary
    CWE-90

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application pgadmin pgadmin_4 < 9.10 Yes

References