CVE-2025-61911 | python-ldap up to 3.4.4 on Python ldap.filter.escape_filter_chars assertion_value special elements into a different plane (special element injection) (GHSA-r7r6-cc7p-4v5m / Nessus ID 270277)
A vulnerability classified as critical was found in python-ldap up to 3.4.4 on Python. The impacted element is the function ldap.filter.escape_filter_chars. Such manipulation of the argument assertion_value leads to failure to sanitize special elements into a different plane (special element injection).
This vulnerability is referenced as CVE-2025-61911. It is possible to launch the attack remotely. No exploit is available.
Upgrading the affected component is advised.