#VU120966 LDAP injection in pgAdmin - CVE-2025-12764
Published: January 5, 2026
pgAdmin
PlanGenius Admin
Description
The vulnerability allows a remote attacker to perform a denial of service attack.
The vulnerability exists due to improper input validation when processing DLAP queries. A remote non-authenticated attacker can pass a specially crafted username to the application causing the DC/LDAP server and the client to process unusual amount of data, leading to a denial of service condition.