LDAP Injection Vulnerability in pgAdmin by pgAdmin Development Team
CVE-2025-12764
7.5HIGH
What is CVE-2025-12764?
pgAdmin versions up to 9.9 are susceptible to an LDAP injection vulnerability during the LDAP authentication process. This allows attackers to insert specially crafted LDAP characters into usernames, ultimately leading to a denial of service by causing excessive data processing by both the LDAP server and the client application. Security measures should be taken to mitigate this vulnerability to protect user data and maintain system integrity.
Affected Version(s)
pgAdmin 4 0
