Fedora LemonLDAP-ng Updates Address Open Redirect Vulnerability CVE-2026-12804

Fedora LemonLDAP-ng Updates Address Open Redirect Vulnerability CVE-2026-12804

First seen 3 Aug 2026, 06:02 UTC Linuxsecurity 97% similarity 45.9

Article Content

Browse articles
ThreatCluster

Fedora has released updates for LemonLDAP-ng versions 2.23.1 and 2.23.2 to address CVE-2026-12804, which is an Open Redirect vulnerability. This flaw allows attackers to manipulate URLs in the SAML Common Domain Cookie Endpoint, potentially leading to unauthorized access. The vulnerability was published on June 21, 2026, and affects users of the LemonLDAP-ng web single sign-on solution. Users are advised to upgrade to the latest versions to mitigate risks associated with this vulnerability. The updates were made available through the dnf package manager. The updates were confirmed by developer Clement Oudot and the Fedora Release Engineering team. Organizations using affected versions are at risk of exploitation if they do not apply the patches promptly.

Key Points: • CVE-2026-12804 is an Open Redirect vulnerability in LemonLDAP-ng affecting versions 2.23.1 and 2.23.2. • Users are urged to update to the latest versions to prevent potential unauthorized access. • The vulnerability was published on June 21, 2026, and is actively being addressed by Fedora.

ThreatCluster AI How this analysis works

Timeline

2026-06-21
CVE-2026-12804 published
An Open Redirect vulnerability in LemonLDAP-ng was disclosed, allowing URL manipulation in SAML endpoints.
Linuxsecurity
2026-07-16
LemonLDAP-ng version 2.23.0 released
Fedora Release Engineering rebuilt LemonLDAP-ng version 2.23.0 as part of the update process.
Linuxsecurity
2026-07-22
LemonLDAP-ng version 2.23.1 released
Clement Oudot released version 2.23.1, which includes fixes for the Open Redirect vulnerability.
Linuxsecurity
2026-07-24
LemonLDAP-ng version 2.23.2 released
Clement Oudot released version 2.23.2, further addressing the Open Redirect vulnerability.
Linuxsecurity

Community

Browse all →

Tracked Entities in This Story