CVE-2025-35431: exploitation status and patch state
CVE-2025-35431 · CVSS 5.4 MEDIUM · EPSS <1%
CISA Thorium does not escape user controlled strings used in LDAP queries. An authenticated remote attacker can modify LDAP authorization data such as group memberships. Fixed in 1.1.1.
Is CVE-2025-35431 exploited?
Not in the CISA KEV catalog.
EPSS puts exploitation in the next 30 days at <1%.
Public exploit code: none found in monitored sources.