CVE-2025-61912 affects python-ldap versions prior to 3.4.5, where the ldap.dn.escape_dn_chars() function incorrectly escapes null bytes (\x00). This flaw allows an attacker to craft malicious input that, when processed by applications using this helper, can cause a client-side denial of service by consistently failing before sending requests to an LDAP server. Rated as Medium severity (CVSS 5.3), this vulnerability has a network attack vector and low attack complexity, requiring no user interaction or privileges. The primary impact is a loss of availability (A:L) for affected client applications. There is currently no evidence of active exploitation, nor are there any public exploit modules or proof-of-concept codes available (Metasploit, Nuclei, ExploitDB). Community discussion and media coverage for this CVE are also minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 3.4.5CPE matchmatch criteria | cpe:2.3:a:python-ldap:python-ldap:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.