ldap.filter.escape_filter_chars. Such manipulation of the argument assertion_value leads to failure to sanitize special elements into a different plane (special element injection).This vulnerability is referenced as CVE-2025-61911. It is possible to launch the attack remotely. No exploit is available.
Upgrading the affected component is advised.