Skip to content
Fedora LemonLDAP-ng Updates Address Open Redirect Vulnerability CVE-2026-12804

Fedora LemonLDAP-ng Updates Address Open Redirect Vulnerability CVE-2026-12804

First seen 3 Aug 2026, 06:02 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster August 4, 2026 at 05:50 UTC
  • CVE-2026-12804 is an Open Redirect vulnerability in LemonLDAP-ng affecting versions 2.23.1 and 2.23.2.
  • Users are urged to update to the latest versions to prevent potential unauthorized access.
  • The vulnerability was published on June 21, 2026, and is actively being addressed by Fedora.

Fedora has released updates for LemonLDAP-ng versions 2.23.1 and 2.23.2 to address CVE-2026-12804, which is an Open Redirect vulnerability. This flaw allows attackers to manipulate URLs in the SAML Common Domain Cookie Endpoint, potentially leading to unauthorized access. The vulnerability was published on June 21, 2026, and affects users of the LemonLDAP-ng web single sign-on solution. Users are advised to upgrade to the latest versions to mitigate risks associated with this vulnerability. The updates were made available through the dnf package manager. The updates were confirmed by developer Clement Oudot and the Fedora Release Engineering team. Organizations using affected versions are at risk of exploitation if they do not apply the patches promptly.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 47d ago How this analysis works

Timeline

2026-06-21
CVE-2026-12804 published
An Open Redirect vulnerability in LemonLDAP-ng was disclosed, allowing URL manipulation in SAML endpoints.
Linuxsecurity
2026-07-16
LemonLDAP-ng version 2.23.0 released
Fedora Release Engineering rebuilt LemonLDAP-ng version 2.23.0 as part of the update process.
Linuxsecurity
2026-07-22
LemonLDAP-ng version 2.23.1 released
Clement Oudot released version 2.23.1, which includes fixes for the Open Redirect vulnerability.
Linuxsecurity
2026-07-24
LemonLDAP-ng version 2.23.2 released
Clement Oudot released version 2.23.2, further addressing the Open Redirect vulnerability.
Linuxsecurity

More articles in this cluster (2)

Following this threat?

Track Fedora and CVE-2026-12804 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed