389-ds:1.4/389-ds-base vulnerabilities
CVEs whose affected-version data names the 389-ds:1.4/389-ds-base package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
2 CVEsRSS
CVE-2026-19843High· 8.4PoCA flaw was found in 389-ds-base
A flaw was found in 389-ds-base. The Cockpit 389 Console's LDAP editor constructs an ldapsearch command by embedding an LDAP entry's distinguished name (DN) into a shell command string without proper escaping. An LDAP user with delegated…
▾ MidnightRed Hat · redhat-ds:11EPSS 0.48%via NVD
CVE-2026-78701Medium· 6.5A flaw was found in 389-ds-base
A flaw was found in 389-ds-base. A remote, authenticated attacker could exploit a vulnerability in the Simple Authentication and Security Layer (SASL) UNBIND process. By sending a specially crafted request, the attacker can cause a conne…
▾ SunlitRed Hat · 389-ds-baseEPSS 0.78%via NVD