Denial of Service Vulnerability in python-ldap Client API by Python
CVE-2025-61912
What is CVE-2025-61912?
The python-ldap client API for Python, specifically versions prior to 3.4.5, contains a vulnerability in the ldap.dn.escape_dn_chars() function. This function improperly escapes NULL bytes by emitting a backslash followed by a literal NUL byte instead of the appropriate RFC-4514 hex representation. As a result, any application utilizing this function with untrusted input can face consistent failures before sending requests to LDAP servers, such as Active Directory. The issue has been addressed in version 3.4.5 with a patch provided to mitigate the risks.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
python-ldap < 3.4.5
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
