Back Linuxsecurity Fedora 43: pgAdmin 4 Critical Remote Code Exec Issues 2025
pgAdmin is the most popular and feature rich Open Source administration and development platform for PostgreSQL, the most advanced Open Source database in the world. Update Information : Update to pgadmin-9.10
pgAdmin is the most popular and feature rich Open Source administration and development
platform for PostgreSQL, the most advanced Open Source database in the world.
Update to pgadmin-9.10
* Sun Nov 16 2025 Sandro Mani - 9.10-1 - Update to 9.10 * Sun Nov 16 2025 Sandro Mani - 9.9-4 - Relax flask-babel and flask-security-too dependencies
* Sun Nov 16 2025 Sandro Mani - 9.10-1 - Update to 9.10 * Sun Nov 16 2025 Sandro Mani - 9.9-4 - Relax flask-babel and flask-security-too dependencies
[ 1 ] Bug #2415411 - CVE-2025-12762 pgadmin4: Remote Code Execution vulnerability when restoring PLAIN-format SQL dumps in server mode (pgAdmin 4) [fedora-42] [ 2 ] Bug #2415412 - CVE-2025-12762 pgadmin4: Remote Code Execution vulnerability when restoring PLAIN-format SQL dumps in server mode (pgAdmin 4) [fedora-43] [ 3 ] Bug #2415415 - CVE-2025-12764 pgadmin4: pgAdmin 4: LDAP injection vulnerability in LDAP authentication flow. [fedora-42] [ 4 ] Bug #2415416 - CVE-2025-12764 pgadmin4: pgAdmin 4: LDAP injection vulnerability in LDAP authentication flow. [fedora-43] [ 5 ] Bug #2415419 - CVE-2025-12765 pgadmin4: pgAdmin 4: LDAP authentication flow vulnerable to TLS certificate verification bypass. [fedora-42] Read the Full Advisory
[ 1 ] Bug #2415411 - CVE-2025-12762 pgadmin4: Remote Code Execution vulnerability when restoring PLAIN-format SQL dumps in server mode (pgAdmin 4) [fedora-42] [ 2 ] Bug #2415412 - CVE-2025-12762 pgadmin4: Remote Code Execution vulnerability when restoring PLAIN-format SQL dumps in server mode (pgAdmin 4) [fedora-43] [ 3 ] Bug #2415415 - CVE-2025-12764 pgadmin4: pgAdmin 4: LDAP injection vulnerability in LDAP authentication flow. [fedora-42] [ 4 ] Bug #2415416 - CVE-2025-12764 pgadmin4: pgAdmin 4: LDAP injection vulnerability in LDAP authentication flow. [fedora-43] [ 5 ] Bug #2415419 - CVE-2025-12765 pgadmin4: pgAdmin 4: LDAP authentication flow vulnerable to TLS certificate verification bypass. [fedora-42]
This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-8a81153971' at the command line. For more information, refer to the dnf documentation available at
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
