Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-cvf4-f829-762v | pgAdmin is affected by an LDAP injection vulnerability |
| Link | Providers |
|---|---|
| https://github.com/pgadmin-org/pgadmin4/issues/9325 |
|
Wed, 19 Nov 2025 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:pgadmin:pgadmin_4:*:*:*:*:*:postgresql:*:* |
Fri, 14 Nov 2025 09:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Pgadmin
Pgadmin pgadmin 4 |
|
| Vendors & Products |
Pgadmin
Pgadmin pgadmin 4 |
Thu, 13 Nov 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-90 | |
| Metrics |
ssvc
|
Thu, 13 Nov 2025 13:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | pgAdmin <= 9.9 is affected by an LDAP injection vulnerability in the LDAP authentication flow that allows an attacker to inject special LDAP characters in the username, causing the DC/LDAP server and the client to process an unusual amount of data DOS. | |
| Title | pgAdmin 4: LDAP injection vulnerability in LDAP authentication flow. | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: PostgreSQL
Published:
Updated: 2025-11-13T14:02:00.502Z
Reserved: 2025-11-05T17:30:07.012Z
Link: CVE-2025-12764
Updated: 2025-11-13T14:01:30.103Z
Status : Analyzed
Published: 2025-11-13T13:15:44.910
Modified: 2025-11-19T21:19:33.810
Link: CVE-2025-12764
No data.
OpenCVE Enrichment
Updated: 2025-11-14T09:28:03Z
Github GHSA