VulnSea

389-ds:1.4 vulnerabilities

CVEs whose affected-version data names the 389-ds:1.4 package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

4 CVEsRSS

CVE-2026-18355High· 7.5
2w ago

A heap buffer overflow flaw was found in the SASL I/O layer of 389 Directory Server (389-ds-base)

A heap buffer overflow flaw was found in the SASL I/O layer of 389 Directory Server (389-ds-base). In sasl_io_start_packet(), the wrapped-record length read from the wire is validated only against an upper bound. A small wire length (0, …

TwilightRed Hat · redhat-ds:11EPSS 0.84%via NVD
CVE-2026-76560High· 7.5
2w ago

A flaw was found in 389 Directory Server

A flaw was found in 389 Directory Server. The SELFDN ACI bind-rule evaluator incorrectly matches an anonymous LDAP client's empty bind DN against an empty stored attribute value, allowing an unauthenticated client to satisfy access contr…

TwilightRed Hat · redhat-ds:11EPSS 0.37%via NVD
CVE-2026-18922Critical· 9.8
2w ago

A flaw was found in 389 Directory Server

A flaw was found in 389 Directory Server. During SASL PLAIN authentication, a stale identity carried in a Cyrus SASL auxiliary property from a prior failed bind attempt can be installed on a connection following a subsequent, unrelated s…

MidnightRed Hat · redhat-ds:11EPSS 0.56%via NVD
CVE-2026-18453High· 7.5
2w ago

A flaw was found in 389 Directory Server

A flaw was found in 389 Directory Server. A missing NULL pointer check in the paged results handling of op_shared_search allows an unauthenticated remote attacker to crash the LDAP server by sending a crafted sequence of search requests …

TwilightRed Hat · redhat-ds:11EPSS 0.85%via NVD
389-ds:1.4 vulnerabilities (CVEs) · VulnSea