LDAP injection in pgAdmin - CVE-2025-12764
Published: January 5, 2026
pgAdmin
Detailed vulnerability description
The vulnerability allows a remote attacker to perform a denial of service attack.
The vulnerability exists due to improper input validation when processing DLAP queries. A remote non-authenticated attacker can pass a specially crafted username to the application causing the DC/LDAP server and the client to process unusual amount of data, leading to a denial of service condition.