python-ldap is a lightweight directory access protocol (LDAP) client API for Python. In versions prior to 3.4.5, ldap.dn.escape_dn_chars() escapes \x00 incorrectly by emitting a backslash followed by a literal NUL byte instead of the RFC-4514 hex form \00. Any application that uses this helper to construct DNs from untrusted input can be made to consistently fail before a request is sent to the LDAP server (e.g., AD), resulting in a client-side denial of service. Version 3.4.5 contains a patch for the issue.
CVSS Details
- CVSS 4.0 Base Score: 5.5 (MEDIUM)
- CVSS 4.0 Vector: (CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X)
- CVSS 3.1 Base Score: 5.3
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade py3-ldap | Jun 18, 2026 | Oct 10, 2025 |
| Amazon Linux Ami 2 | — | Upgrade python-ldapUpgrade python-ldap-debuginfo | May 20, 2026 | May 20, 2026 |
| Debian | — | Upgrade python-ldap | May 17, 2026 | May 17, 2026 |
| Huawei Euleros 2_0_sp10 | — | Upgrade python3-ldapUpgrade python-ldap-help | Mar 17, 2026 | Mar 17, 2026 |
| Huawei Euleros 2_0_sp11 | — | Upgrade python-ldap-helpUpgrade python3-ldap | Mar 17, 2026 | Mar 17, 2026 |
| Huawei Euleros 2_0_sp12 | — | Upgrade python-ldap-helpUpgrade python3-ldap | Mar 17, 2026 | Mar 17, 2026 |
| Huawei Euleros 2_0_sp13 | — | Upgrade python-ldap-helpUpgrade python3-ldap | Dec 12, 2025 | Dec 11, 2025 |
| Redhat_linux | — | No solution exists | Jul 17, 2026 | Oct 10, 2025 |
| Suse | — | Upgrade python3-ldap | Dec 5, 2025 | Oct 21, 2025 |
| Ubuntu | — | Upgrade python-ldap (Ubuntu Pro)Upgrade python3-ldapUpgrade python3-ldap (Ubuntu Pro) | Oct 21, 2025 | Oct 10, 2025 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub