Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

Red Hat Directory Server 11 — Vulnerabilities & Security Advisories 18

All 18 CVE vulnerabilities found in Red Hat Directory Server 11, with AI-generated Chinese analysis, references, and POCs.

This page aggregates security vulnerabilities affecting Red Hat Directory Server 11, focusing on specific weakness types within the Directory Services category. It collects reported security flaws, including buffer overflows, privilege escalation issues, and denial of service bugs, covering advisories published from 2023 through 2024. Readers can use this resource to track the vendor’s latest security advisories, understand common weakness classes affecting directory services, and review the historical vulnerability landscape for this specific product version. The data helps security teams identify recurring threat patterns and assess the overall security posture of deployments running Red Hat Directory Server 11.

Vendor: Red Hat

CVE ID Title CVSS Severity Published
CVE-2026-18663 389-ds-base: 389-ds-base: pre-authentication double-free in get_ldapmessage_controls_ext() via critical session tracking control CWE-415 5.9 Medium 2026-08-12
CVE-2026-19404 389-ds-base: 389-ds-base: missing authorization allows anonymous clients to start or abort cleanallruv replication maintenance CWE-862 6.5 Medium 2026-08-10
CVE-2026-18651 389-ds-base: 389-ds-base: sasl plain bind installs connection credentials before account-lock check, allowing continued access as a locked account CWE-287 5.4 Medium 2026-08-03
CVE-2026-16560 389-ds-base: 389-ds-base: heap-buffer-overflow in rdn_av_swap on quoted multivalued rdn CWE-1220 5.3 Medium 2026-07-22
CVE-2026-15041 389-ds-base: 389-ds-base: non-constant-time comparison in pbkdf2-sha256 password verification CWE-208 3.7 Low 2026-07-08
CVE-2026-14969 389-ds-base: 389-ds-base: static initialization vector in aes-cbc/3des-cbc attribute encryption CWE-329 4.4 Medium 2026-07-07
CVE-2026-14940 389-ds-base: 389-ds-base: heap-buffer-overflow in dn normalization via quoted multivalued rdn CWE-122 5.3 Medium 2026-07-07
CVE-2026-11791 389-ds-base: 389-ds-base: use-after-free in schema reload via attr_syntax_swap_ht() CWE-416 5.0 Medium 2026-06-18
CVE-2026-12528 389-ds-base: 389-ds-base: heap-buffer-overflows in __aclp__normalize_acltxt() CWE-787 5.4 Medium 2026-06-17
CVE-2026-11884 389-ds-base: 389-ds-base: heap buffer overflow in schema objectclass serialization due to missing oc_superior in size calculation CWE-122 6.5 Medium 2026-06-10
CVE-2026-11792 389-ds-base: 389-ds-base: heap buffer overflow in audit log password masking (create_masked_entry_string) CWE-122 3.3 Low 2026-06-09
CVE-2026-11793 389-ds-base: 389-ds-base: stack buffer overflow in checkprefix() algorithm id parsing CWE-121 4.9 Medium 2026-06-09
CVE-2026-11790 389-ds-base: 389-ds-base: pbkdf2 password storage plugin unbounded iteration count denial of service CWE-400 4.9 Medium 2026-06-09
CVE-2026-11789 389-ds-base: 389-ds-base: smd5 password storage plugin salt length integer underflow crash CWE-191 4.9 Medium 2026-06-09
CVE-2026-11787 389-ds-base: 389-ds-base: heap buffer over-read in ldap_utf8prev() via str2simple filter parsing CWE-126 5.0 Medium 2026-06-09
CVE-2026-11786 389-ds-base: 389-ds-base: heap out-of-bounds read in ldif parser str2entry_state_information_from_type() CWE-125 1.9 Low 2026-06-09
CVE-2026-11785 389-ds-base: 389-ds-base: partial stack address information leak via ber_printf type confusion in sso token handler CWE-843 4.3 Medium 2026-06-09
CVE-2026-11611 389-ds-base: 389-ds-base: content sync plugin unbounded queue growth and race conditions CWE-400 6.5 Medium 2026-06-08

All 18 known CVE vulnerabilities affecting Red Hat Directory Server 11 with full Chinese analysis, references, and POCs where available.