Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2025-61912

21
FAUCET Score

CVE-2025-61912 affects python-ldap versions prior to 3.4.5, where the ldap.dn.escape_dn_chars() function incorrectly escapes null bytes (\x00). This flaw allows an attacker to craft malicious input that, when processed by applications using this helper, can cause a client-side denial of service by consistently failing before sending requests to an LDAP server. Rated as Medium severity (CVSS 5.3), this vulnerability has a network attack vector and low attack complexity, requiring no user interaction or privileges. The primary impact is a loss of availability (A:L) for affected client applications. There is currently no evidence of active exploitation, nor are there any public exploit modules or proof-of-concept codes available (Metasploit, Nuclei, ExploitDB). Community discussion and media coverage for this CVE are also minimal.

Impacted Technologies

VendorProductVersion(s)CPE
< 3.4.5CPE matchmatch criteria
cpe:2.3:a:python-ldap:python-ldap:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 4.0

5.5MEDIUM

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Attack Vector
NETWORK
Attack Complexity
LOW
Attack Requirements
NONE
Privileges Required
NONE
User Interaction
NONE
VS Confidentiality
NONE
VS Integrity
NONE
VS Availability
LOW
SS Confidentiality
NONE
SS Integrity
NONE
SS Availability
NONE
Exploit Maturity
PROOF_OF_CONCEPT
CvssVersion
4.0

Exploit Intelligence

EPSS Score
0.43%
Probability of exploitation in next 30 days
EPSS Percentile
35.0%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0043 is in the 22nd percentile among its peer group of 23,723 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (10)

github_advisorypatch availablevia nvd_reference
View patch
pippatch availablevia ghsa
Product: python-ldapFixed in: 3.4.5
redhatvendor investigatingvia redhat_api
Product: Red Hat Ansible Automation Platform 2Fixed in: python3.11-ldap
redhatvendor investigatingvia redhat_api
Product: Red Hat Ansible Automation Platform 2Fixed in: python3x-ldap
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 10Fixed in: python-ldap
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: python-ldap
redhatvendor investigatingvia redhat_api
Product: Red Hat Quay 3Fixed in: quay/quay-rhel8
redhatvendor investigatingvia redhat_api
Product: Red Hat Satellite 6Fixed in: python3.12-ldap
redhatvendor investigatingvia redhat_api
Product: Red Hat Satellite 6Fixed in: python-ldap
redhatvendor investigatingvia redhat_api
Product: Red Hat Ansible Automation Platform 2Fixed in: automation-controller

Vendor Advisories (2)

pipGHSA-p34h-wq7j-h5v6medium

python-ldap is Vulnerable to Improper Encoding or Escaping of Output and Improper Null Termination

Oct 10, 2025
redhatCVE-2025-61912Moderate

python-ldap: python-ldap Vulnerable to Improper Encoding or Escaping of Output and Improper Null Termination

Oct 10, 2025

References

github.com / python-ldap/python-ldap/commit/6ea80326a34ee6093219628d7690bced50c49a3f
Patch
github.com / python-ldap/python-ldap/releases/tag/python-ldap-3.4.5
Release Notes
github.com / python-ldap/python-ldap/security/advisories/GHSA-p34h-wq7j-h5v6
ExploitThird Party Advisory