{"id":"CVE-2025-61912","summary":"python-ldap Vulnerable to Improper Encoding or Escaping of Output and Improper Null Termination","details":"python-ldap is a lightweight directory access protocol (LDAP) client API for Python. In versions prior to 3.4.5, ldap.dn.escape_dn_chars() escapes \\x00 incorrectly by emitting a backslash followed by a literal NUL byte instead of the RFC-4514 hex form \\00. Any application that uses this helper to construct DNs from untrusted input can be made to consistently fail before a request is sent to the LDAP server (e.g., AD), resulting in a client-side denial of service. Version 3.4.5 contains a patch for the issue.","aliases":["GHSA-p34h-wq7j-h5v6","PYSEC-2026-1846"],"modified":"2026-08-12T03:51:11.209618335Z","published":"2025-10-10T22:04:25.028Z","related":["CGA-38c2-5hr9-5r4q","SUSE-SU-2025:3695-1","SUSE-SU-2025:3714-1","SUSE-SU-2026:20933-1","openSUSE-SU-2025:15637-1","openSUSE-SU-2026:20421-1"],"database_specific":{"cna_assigner":"GitHub_M","cwe_ids":["CWE-116","CWE-170"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/61xxx/CVE-2025-61912.json"},"references":[{"type":"WEB","url":"https://github.com/python-ldap/python-ldap/releases/tag/python-ldap-3.4.5"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/61xxx/CVE-2025-61912.json"},{"type":"ADVISORY","url":"https://github.com/python-ldap/python-ldap/security/advisories/GHSA-p34h-wq7j-h5v6"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-61912"},{"type":"FIX","url":"https://github.com/python-ldap/python-ldap/commit/6ea80326a34ee6093219628d7690bced50c49a3f"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/python-ldap/python-ldap","events":[{"introduced":"0"},{"fixed":"bf666e918615b00dbcd1bbe71542522eedfdffc1"},{"fixed":"6ea80326a34ee6093219628d7690bced50c49a3f"}],"database_specific":{"source":["CPE_RANGE","REFERENCES"],"cpe":"cpe:2.3:a:python-ldap:python-ldap:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"fixed":"3.4.5"}]}}],"versions":["python-ldap-3.4.4","python-ldap-3.4.3","python-ldap-3.4.2","python-ldap-3.4.1","python-ldap-3.4.0","python-ldap-3.3.0","python-ldap-3.2.0","python-ldap-3.1.0","python-ldap-3.0.0","python-ldap-3.0.0b4","python-ldap-3.0.0b3","python-ldap-3.0.0b2","python-ldap-3.0.0b1","python-ldap-2.5.1","python-ldap-2.5.0","python-ldap-2.4.45","python-ldap-2.4.44","python-ldap-2.4.43","python-ldap-2.4.42","python-ldap-2.4.41","python-ldap-2.4.40","python-ldap-2.4.39","python-ldap-2.4.38","python-ldap-2.4.37","python-ldap-2.4.36","python-ldap-2.4.35","python-ldap-2.4.33","python-ldap-2.4.32","python-ldap-2.4.31","python-ldap-2.4.30","python-ldap-2.4.29","python-ldap-2.4.28","python-ldap-2.4.27","python-ldap-2.4.26","python-ldap-2.4.23","python-ldap-2.4.21","python-ldap-2.4.20","python-ldap-2.4.13","python-ldap-2.4.12","python-ldap-2.4.10","python-ldap-2.4.9","python-ldap-2.4.7","python-ldap-2.4.6","python-ldap-2.4.4","python-ldap-2.3.13","python-ldap-2.3.11","python-ldap-2.3.10","python-ldap-2.3.9","python-ldap-2.3.8","python-ldap-2.3.7","python-ldap-2.3.4","python-ldap-2.3.3","python-ldap-2.3.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-61912.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P"}]}