CVE-2021-46823Medium· 6.5▾ SunlitDenial of Service in python-ldap
▾ Sunlit zone — Low / medium · no exploitation signal
impact 35.8 · likelihood 0.4 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 8.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
1.7%
1.7% → 1.9%
python-ldap before 3.4.0 is vulnerable to a denial of service when ldap.schema is used for untrusted schema definitions, because of a regular expression denial of service (ReDoS) flaw in the LDAP schema parser. By sending crafted regex input, a remote authenticated attacker could exploit this vulnerability to cause a denial of service condition.
python-ldap < 3.4.0Upgrade to a patched release:
python-ldap 3.4.0Connected by shared product, vendor, weakness, or advisory.