Linuxsecurity Fedora LemonLDAP-ng Updates Address Open Redirect Vulnerability CVE-2026-12804
Article Content
- •CVE-2026-12804 is an Open Redirect vulnerability in LemonLDAP-ng affecting versions 2.23.1 and 2.23.2.
- •Users are urged to update to the latest versions to prevent potential unauthorized access.
- •The vulnerability was published on June 21, 2026, and is actively being addressed by Fedora.
Fedora has released updates for LemonLDAP-ng versions 2.23.1 and 2.23.2 to address CVE-2026-12804, which is an Open Redirect vulnerability. This flaw allows attackers to manipulate URLs in the SAML Common Domain Cookie Endpoint, potentially leading to unauthorized access. The vulnerability was published on June 21, 2026, and affects users of the LemonLDAP-ng web single sign-on solution. Users are advised to upgrade to the latest versions to mitigate risks associated with this vulnerability. The updates were made available through the dnf package manager. The updates were confirmed by developer Clement Oudot and the Fedora Release Engineering team. Organizations using affected versions are at risk of exploitation if they do not apply the patches promptly.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track Fedora and CVE-2026-12804 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Global Phishing Campaign Exploits Google Services for Credential Theft A large-scale phishing campaign is leveraging trusted Google infrastructure to bypass email security measures and steal credentials. The operation uses a multi-stage redirect network that includes six distinct Google services, making it difficult for security systems to detect malicious activity. Victims are presented…
Moderate Patch Released for openSUSE python-Authlib Vulnerability CVE-2026-41479 A moderate patch has been released for the python-Authlib library to address CVE-2026-41479, which allows crafted authorization requests to cause unauthenticated open redirects. This vulnerability affects openSUSE Leap 15.6 and Python 3 Module 15-SP7. The CVE was published on June 22, 2026, and has a CVSS score of…