VulnSea

389_directory_server vulnerabilities

CVEs whose affected-version data names the 389_directory_server package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

4 CVEsRSS

CVE-2026-18651Medium· 5.4
1mo ago

A flaw was found in 389 Directory Server

A flaw was found in 389 Directory Server. During SASL PLAIN authentication, the server installs connection-level bind credentials before performing the account-lock check. If the account is subsequently found to be locked, the bind is re…

Sunlitredhat · directory_serverEPSS 0.17%via NVD
CVE-2026-15722High· 7.5
1mo ago

A stack buffer overflow flaw was found in 389 Directory Server (389-ds-base)

A stack buffer overflow flaw was found in 389 Directory Server (389-ds-base). The get_ruvelement_from_berval() function in repl5_ruv.c copies digit characters from a network-supplied RUV berval into a fixed 16-byte stack buffer without b…

Twilightredhat · directory_serverEPSS 0.83%via NVD
CVE-2026-11788Medium· 5.9
3mo ago

A flaw was found in 389 Directory Server

A flaw was found in 389 Directory Server. The dereference control plugin does not check for allocation failure before using a BER structure, allowing an unauthenticated remote attacker to crash the LDAP server when the system is under me…

Sunlitredhat · directory_serverEPSS 0.56%via NVD
CVE-2026-11793Medium· 4.9
3mo ago

A stack buffer overflow flaw was found in 389 Directory Server

A stack buffer overflow flaw was found in 389 Directory Server. The checkPrefix() function in pw.c copies an attacker-controlled algorithm ID into a 256-byte stack buffer without bounds checking when parsing reversible-encrypted attribut…

Sunlitredhat · 389_directory_serverEPSS 0.28%via NVD
389_directory_server vulnerabilities (CVEs) · VulnSea