CVE-2025-0367: Splunk Supporting Add-On For Active Directory

Medium severity, CVSS 6.5. EPSS: 0.5% chance of exploitation in the next 30 days.

In versions 3.1.0 and lower of the Splunk Supporting Add-on for Active Directory, also known as SA-ldapsearch, a vulnerable regular expression pattern could lead to a Regular Expression Denial of Service (ReDoS) attack.

Affected products

  • Splunk Splunk Supporting Add-On For Active Directory: from 3.1, before 3.1.1 (fixed in 3.1.1)

Published 2025-01-30. Last modified 2026-06-17.