CVE-2025-12764: Pgadmin 4

High severity, CVSS 7.5. EPSS: 0.4% chance of exploitation in the next 30 days.

pgAdmin <= 9.9  is affected by an LDAP injection vulnerability in the LDAP authentication flow that allows an attacker to inject special LDAP characters in the username, causing the DC/LDAP server and the client to process an unusual amount of data DOS.

Affected products

  • Pgadmin Pgadmin 4: before 9.10 (fixed in 9.10)

Published 2025-11-13. Last modified 2026-10-07.