redhat-ds:11 vulnerabilities
CVEs whose affected-version data names the redhat-ds:11 package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
5 CVEsRSS
CVE-2026-18355High· 7.5A heap buffer overflow flaw was found in the SASL I/O layer of 389 Directory Server (389-ds-base)
A heap buffer overflow flaw was found in the SASL I/O layer of 389 Directory Server (389-ds-base). In sasl_io_start_packet(), the wrapped-record length read from the wire is validated only against an upper bound. A small wire length (0, …
CVE-2026-76560High· 7.5A flaw was found in 389 Directory Server
A flaw was found in 389 Directory Server. The SELFDN ACI bind-rule evaluator incorrectly matches an anonymous LDAP client's empty bind DN against an empty stored attribute value, allowing an unauthenticated client to satisfy access contr…
CVE-2026-19843High· 8.4PoCA flaw was found in 389-ds-base
A flaw was found in 389-ds-base. The Cockpit 389 Console's LDAP editor constructs an ldapsearch command by embedding an LDAP entry's distinguished name (DN) into a shell command string without proper escaping. An LDAP user with delegated…
CVE-2026-18922Critical· 9.8A flaw was found in 389 Directory Server
A flaw was found in 389 Directory Server. During SASL PLAIN authentication, a stale identity carried in a Cyrus SASL auxiliary property from a prior failed bind attempt can be installed on a connection following a subsequent, unrelated s…
CVE-2026-18453High· 7.5A flaw was found in 389 Directory Server
A flaw was found in 389 Directory Server. A missing NULL pointer check in the paged results handling of op_shared_search allows an unauthenticated remote attacker to crash the LDAP server by sending a crafted sequence of search requests …