{"id":"GHSA-qcxq-75wr-5cm8","aliases":[],"url":"https://o3.security/vulnerability/GHSA-qcxq-75wr-5cm8","summary":"ldap3_proto has LDAP Filter stack exhaustion","details":"### Impact\nLDAP queries are not validated for depth, which can cause the parser (both PEG and ASN) to exhaust the stack. This *may* cause a denial of service in applications that process queries.\n\n### Workarounds\nN/A\n\n### References\nRelated to GHSA-r5fr-9gmv-jggh","published":"2026-05-06T23:39:47Z","modified":"2026-08-14T19:30:08.115903092Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"crates.io","name":"ldap3_proto","fixedVersion":"0.7.1"}],"fix":null,"references":[{"type":"WEB","url":"https://github.com/kanidm/ldap3/security/advisories/GHSA-qcxq-75wr-5cm8"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-r5fr-9gmv-jggh"},{"type":"PACKAGE","url":"https://github.com/kanidm/ldap3"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-14T19:30:08.115903092Z"}}