THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-xghw-p77p-3r7x (medium) — Fabric CA Developer's Guide: LDAP Injection via Unescaped Username in GetUser Filter

[GHSA] GHSA-xghw-p77p-3r7x (medium) — Fabric CA Developer's Guide: LDAP Injection via Unescaped Username in GetUser Filter

medgithub_advisoriesPublished 2026-08-14

GHSA-xghw-p77p-3r7x Severity: medium CVE: CVE-2026-53658

Fabric CA Developer's Guide: LDAP Injection via Unescaped Username in GetUser Filter

When fabric-ca is configured with an LDAP backend, the username from HTTP Basic authentication is included in an LDAP uid search filter without proper escaping. An unauthenticated attacker with network access to the CA enrollment endpoint could exploit thi

Indicators of compromise

Original source: https://github.com/advisories/GHSA-xghw-p77p-3r7x