CVE detail
CVE-2026-12804
A vulnerability was detected in lemonldap-ng up to 2.23.0. Impacted is an unknown function in the library lemonldap-ng-portal/lib/Lemonldap/NG/Portal/CDC.pm of the component SAML Common Domain Cookie Endpoint. Performing a manipulation of the argument url results in open redirect. The attack is possible to be carried out remotely. The exploit is now public and may be used. Applying a patch is the recommended action to fix this issue. The vendor confirms, that "it has been fixed some days ago and will be available in 2.23.1. CDC is quite never used, so the impact is very low."
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 19.5 · diversity 10.0 · KEV 0.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 0
- within the 30d window
- Peak daily
- 0
- highest bucket
Evidence
Source links by recency
6 source links · newest first
- https://vuldb.com/vuln/372598/ctivuldb.com
No excerpt available.
Exploitvuldb.comJun 21, 2026, 7:16 PM - https://vuldb.com/vuln/372598vuldb.com
No excerpt available.
Exploitvuldb.comJun 21, 2026, 7:16 PM - https://vuldb.com/submit/836105vuldb.com
No excerpt available.
Exploitvuldb.comJun 21, 2026, 7:16 PM - https://vuldb.com/cve/CVE-2026-12804vuldb.com
No excerpt available.
Exploitvuldb.comJun 21, 2026, 7:16 PM No excerpt available.
referencegitlab.ow2.orgJun 21, 2026, 7:16 PMNo excerpt available.
referencegitlab.ow2.orgJun 21, 2026, 7:16 PM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2026-14171CVSS 6.1 · Medium
An unauthenticated remote attacker can abuse the improper validation of the post-login redirect of the web-UI to trick users to a malicious website. This can result in a loss of…
- CVE-2026-53669CVSS 5.1 · Medium
React Router is a router for React. Versions 6.0.0 through 7.17.0 are vulnerable to Open Redirtect through use of backslashes in <Link> and useNavigate. This issue is a follow up…
- CVE-2026-53668CVSS 6.9 · Medium
React Router is a router for React. In versions 6.30.2 through 6.30.4 and 7.9.6 through 7.12.0, applications that allow open redirects are vulnerable to XSS. An attacker could cra…
- CVE-2026-59730CVSS 2.1 · Low
Astro is a web framework for content-driven websites. In versions 8.1.0 through 11.0.1, when trailingSlash: 'always' is configured, the @astrojs/node standalone server's static fi…
- CVE-2026-64645CVSS 8.3 · High
Next.js is a React framework for building full-stack web applications. In versions 12.0.0 through 15.5.20 and 16.0.0 through 16.2.10, a rewrites() or redirects() rule that builds…
- CVE-2026-14236CVSS 4.7 · Medium
The Contact Form 7 WordPress plugin before 2.5 does not validate the host of a user-supplied return URL before using it as the success and cancel redirect targets of a Stripe che…