CVE-2025-31510
published 2026-01-16CVE-2025-31510: In the portal in LemonLDAP::NG before 2.21.0, cross-site scripting (XSS) allows remote attackers to inject arbitrary web script or HTML (into the login page)…
PriorityP341high7.2CVSS 3.1
AVNACLPRNUINSCCLILAN
EPSS
0.38%
30.3th percentile
In the portal in LemonLDAP::NG before 2.21.0, cross-site scripting (XSS) allows remote attackers to inject arbitrary web script or HTML (into the login page) via the tab parameter, for Choice authentication.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | lemonldap-ng | < lemonldap-ng 2.16.1+ds-deb12u6 (bookworm) | lemonldap-ng 2.16.1+ds-deb12u6 (bookworm) |
| lemonldap-ng | lemonldap_ng | >= 2.0.8 < 2.16.5 | 2.16.5 |
| lemonldap-ng | lemonldap_ng | >= 2.17.0 < 2.21.0 | 2.21.0 |
CVSS provenance
nvdv3.17.2HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
osv7.2HIGH
vendor_debian7.2HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
CVE-2025-31510: In the portal in LemonLDAP::NG before 2
osv·2026-01-16·CVSS 7.2
CVE-2025-31510 [HIGH] CVE-2025-31510: In the portal in LemonLDAP::NG before 2
In the portal in LemonLDAP::NG before 2.21.0, cross-site scripting (XSS) allows remote attackers to inject arbitrary web script or HTML (into the login page) via the tab parameter, for Choice authentication.
GHSA
GHSA-55mm-vp96-5r7h: In the portal in LemonLDAP::NG before 2
ghsa_unreviewed·2026-01-16
CVE-2025-31510 [HIGH] CWE-79 GHSA-55mm-vp96-5r7h: In the portal in LemonLDAP::NG before 2
In the portal in LemonLDAP::NG before 2.21.0, cross-site scripting (XSS) allows remote attackers to inject arbitrary web script or HTML (into the login page) via the tab parameter, for Choice authentication.
Debian
CVE-2025-31510: lemonldap-ng - In the portal in LemonLDAP::NG before 2.21.0, cross-site scripting (XSS) allows ...
vendor_debian·2025·CVSS 7.2
CVE-2025-31510 [HIGH] CVE-2025-31510: lemonldap-ng - In the portal in LemonLDAP::NG before 2.21.0, cross-site scripting (XSS) allows ...
In the portal in LemonLDAP::NG before 2.21.0, cross-site scripting (XSS) allows remote attackers to inject arbitrary web script or HTML (into the login page) via the tab parameter, for Choice authentication.
Scope: local
bookworm: resolved (fixed in 2.16.1+ds-deb12u6)
bullseye: resolved (fixed in 2.0.11+ds-4+deb11u7)
forky: resolved (fixed in 2.21.0+ds-1)
sid: resolved (fixed in 2.21.0+ds-1)
trixie: resolved (fixed in 2.21.0+ds-1)
No detection rules found.
No public exploits indexed.
Wiz
CVE-2025-31510 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 7.2
CVE-2025-31510 [HIGH] CVE-2025-31510 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-31510 :
Linux Debian vulnerability analysis and mitigation
In the portal in LemonLDAP::NG before 2.21.0, cross-site scripting (XSS) allows remote attackers to inject arbitrary web script or HTML (into the login page) via the tab parameter, for Choice authentication.
Source : NVD
## 7.2
Score
Published January 16, 2026
Severity HIGH
CNA Score 7.2
Affected Technologies
Linux Debian
Echo
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 1.3
Exploitation Probability (EPSS) N/A
Affected packages and libraries
lemonldap-ng
Sources
NVD
Debian 11, 12, 13 Severity HIGH Has Fix Added at: Apr 08, 2025
Debian 14 Severity HIGH Has Fix Added at: Aug 10, 2025
Echo Severity HIGH Has
Bugzilla
CVE-2026-31510 kernel: Bluetooth: L2CAP: Fix null-ptr-deref on l2cap_sock_ready_cb
bugzilla·2026-04-22
CVE-2026-31510 [MEDIUM] CVE-2026-31510 kernel: Bluetooth: L2CAP: Fix null-ptr-deref on l2cap_sock_ready_cb
CVE-2026-31510 kernel: Bluetooth: L2CAP: Fix null-ptr-deref on l2cap_sock_ready_cb
In the Linux kernel, the following vulnerability has been resolved:
Bluetooth: L2CAP: Fix null-ptr-deref on l2cap_sock_ready_cb
Before using sk pointer, check if it is null.
Fix the following:
KASAN: null-ptr-deref in range [0x0000000000000260-0x0000000000000267]
CPU: 0 UID: 0 PID: 5985 Comm: kworker/0:5 Not tainted 7.0.0-rc4-00029-ga989fde763f4 #1 PREEMPT(full)
Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.17.0-9.fc43 06/10/2025
Workqueue: events l2cap_info_timeout
RIP: 0010:kasan_byte_accessible+0x12/0x30
Code: 79 ff ff ff 0f 1f 40 00 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 0f 1f 40 d6 48 c1 ef 03 48 b8 00 00 00 00 00 fc ff df b6 04 07 3c 08 0f 92 c0 c3 cc cce
veth0_macvtap: enter
2026-01-16
Published