dirsrv/dirsrv-container-rhel10 vulnerabilities
CVEs whose affected-version data names the dirsrv/dirsrv-container-rhel10 package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
4 CVEsRSS
CVE-2026-18355High· 7.5A heap buffer overflow flaw was found in the SASL I/O layer of 389 Directory Server (389-ds-base)
A heap buffer overflow flaw was found in the SASL I/O layer of 389 Directory Server (389-ds-base). In sasl_io_start_packet(), the wrapped-record length read from the wire is validated only against an upper bound. A small wire length (0, …
CVE-2026-76560High· 7.5A flaw was found in 389 Directory Server
A flaw was found in 389 Directory Server. The SELFDN ACI bind-rule evaluator incorrectly matches an anonymous LDAP client's empty bind DN against an empty stored attribute value, allowing an unauthenticated client to satisfy access contr…
CVE-2026-18453High· 7.5A flaw was found in 389 Directory Server
A flaw was found in 389 Directory Server. A missing NULL pointer check in the paged results handling of op_shared_search allows an unauthenticated remote attacker to crash the LDAP server by sending a crafted sequence of search requests …
CVE-2026-78701Medium· 6.5A flaw was found in 389-ds-base
A flaw was found in 389-ds-base. A remote, authenticated attacker could exploit a vulnerability in the Simple Authentication and Security Layer (SASL) UNBIND process. By sending a specially crafted request, the attacker can cause a conne…