← Back to CVE search

CVE-2026-11788

389 Directory Server

Description

A flaw was found in 389 Directory Server. The dereference control plugin does not check for allocation failure before using a BER structure, allowing an unauthenticated remote attacker to crash the LDAP server when the system is under memory pressure.

CVSS 5.9EPSS 0.346%Risk 0.61
View source
Published
2026-06-09 14:16:36
Affected versions
unknown
Type
Core software
Last modified
2026-07-23 08:10:00
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
Operating systems
Linux