LDAP Injection Vulnerability in pgAdmin by pgAdmin Development Team
CVE-2025-12764

7.5HIGH

Key Information:

Status
Vendor
CVE Published:
13 November 2025

What is CVE-2025-12764?

pgAdmin versions up to 9.9 are susceptible to an LDAP injection vulnerability during the LDAP authentication process. This allows attackers to insert specially crafted LDAP characters into usernames, ultimately leading to a denial of service by causing excessive data processing by both the LDAP server and the client application. Security measures should be taken to mitigate this vulnerability to protect user data and maintain system integrity.

Affected Version(s)

pgAdmin 4 0

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-12764 : LDAP Injection Vulnerability in pgAdmin by pgAdmin Development Team