Red Hat Directory Server

7 known vulnerabilities in Red Hat Directory Server, 2 critical, with patch priority, exploit likelihood and the news covering them.

Latest vulnerabilities

  • CVE-2026-86345 CVSS 9.0 critical A flaw was found in 389-ds-base. The server does not discard plaintext bytes already buffered from a client connection when negotiating…
  • CVE-2026-86344 CVSS 7.5 high A flaw was found in 389-ds-base. An unauthenticated remote attacker can send a complete LDAP operation followed by the first bytes of an…
  • CVE-2026-19843 CVSS 8.4 high A flaw was found in 389-ds-base. The Cockpit 389 Console's LDAP editor constructs an ldapsearch command by embedding an LDAP entry's…
  • CVE-2026-18922 CVSS 9.8 critical A flaw was found in 389 Directory Server. During SASL PLAIN authentication, a stale identity carried in a Cyrus SASL auxiliary property…
  • CVE-2026-18453 CVSS 7.5 high A flaw was found in 389 Directory Server. A missing NULL pointer check in the paged results handling of op_shared_search allows an…
  • CVE-2026-18355 CVSS 7.5 high A heap buffer overflow flaw was found in the SASL I/O layer of 389 Directory Server (389-ds-base). In sasl_io_start_packet(), the…
  • CVE-2026-76560 CVSS 7.5 high A flaw was found in 389 Directory Server. The SELFDN ACI bind-rule evaluator incorrectly matches an anonymous LDAP client's empty bind DN…