CVE-2025-12764: Pgadmin 4
High severity, CVSS 7.5. EPSS: 0.4% chance of exploitation in the next 30 days.
pgAdmin <= 9.9 is affected by an LDAP injection vulnerability in the LDAP authentication flow that allows an attacker to inject special LDAP characters in the username, causing the DC/LDAP server and the client to process an unusual amount of data DOS.
Affected products
- Pgadmin Pgadmin 4: before 9.10 (fixed in 9.10)
Published 2025-11-13. Last modified 2026-10-07.