Linuxsecurity
Fedora LemonLDAP-ng Updates Address Open Redirect Vulnerability CVE-2026-12804
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
Fedora has released updates for LemonLDAP-ng versions 2.23.1 and 2.23.2 to address CVE-2026-12804, which is an Open Redirect vulnerability. This flaw allows attackers to manipulate URLs in the SAML Common Domain Cookie Endpoint, potentially leading to unauthorized access. The vulnerability was published on June 21, 2026, and affects users of the LemonLDAP-ng web single sign-on solution. Users are advised to upgrade to the latest versions to mitigate risks associated with this vulnerability. The updates were made available through the dnf package manager. The updates were confirmed by developer Clement Oudot and the Fedora Release Engineering team. Organizations using affected versions are at risk of exploitation if they do not apply the patches promptly.
Key Points: • CVE-2026-12804 is an Open Redirect vulnerability in LemonLDAP-ng affecting versions 2.23.1 and 2.23.2. • Users are urged to update to the latest versions to prevent potential unauthorized access. • The vulnerability was published on June 21, 2026, and is actively being addressed by Fedora.