Security advisories in the AI and data stack

Severe, 6 weeks2979Projects319
Red HatCVE-2026-86345

A flaw was found in 389-ds-base

Critical9.0CVE-2026-86345 · Published Oct 2, 2026

A flaw was found in 389-ds-base. The server does not discard plaintext bytes already buffered from a client connection when negotiating StartTLS, allowing an on-path attacker to inject a crafted LDAP message that is processed after the TLS upgrade and whose response is delivered to the client in place of the client's own pending operation's response, due to messageID collision. This can cause a client application to treat a failed authentication (bind) attempt as successful.

Red Hat advisory

Affected versions

PackageAffectedFixed in
Red Hat Directory Server 11
Product
all versionsNo fix yet
all versionsNo fix yet
Red Hat Directory Server 12
Product
all versionsNo fix yet
all versionsNo fix yet
Red Hat Directory Server 13
Product
all versionsNo fix yet
Red Hat Enterprise Linux 10
Product
all versionsNo fix yet
Red Hat Enterprise Linux 6
Product
all versionsNo fix yet
Red Hat Enterprise Linux 7
Product
all versionsNo fix yet
Red Hat Enterprise Linux 8
Product
all versionsNo fix yet
all versionsNo fix yet
Red Hat Enterprise Linux 9
Product
all versionsNo fix yet
Details and references
CVSS 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
Severity from
the vendor (its own CVE record or advisory)
Weakness
CWE-923

More Red Hat advisories

All Red Hat
Advisory
Red Hat FreeType: resource exhaustion
Medium5.5Oct 2
Red Hat 389-ds-base: resource exhaustion
High7.5Oct 1
Red Hat Satellite 6: SQL injection
Medium6.5Oct 1
Red Hat Satellite 6: observable discrepancy
Medium4.3Oct 1
Red Hat Satellite 6: command injection
Medium5.3Oct 1
Red Hat Satellite 6: command injection
Medium6.7Oct 1