VDB

CVE-2026-78701

CVE-2026-78701 PUBLISHED CVSS 6.5 MEDIUM

Reported by redhat · Published August 25, 2026

A flaw was found in 389-ds-base. A remote, authenticated attacker could exploit a vulnerability in the Simple Authentication and Security Layer (SASL) UNBIND process. By sending a specially crafted request, the attacker can cause a connection to stall, leading to resource exhaustion and a Denial of Service (DoS) for the server.

Risk Scores

CVSS 3.1
6.5
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Affected Products

VendorProductVersions
Red HatRed Hat Enterprise Linux 100:3.2.0-10.el10_2
Red HatRed Hat Enterprise Linux 90:2.8.0-10.el9_8
Red HatRed Hat Directory Server 13.21788851765
Red HatRed Hat Directory Server 11
Red HatRed Hat Directory Server 12
Red HatRed Hat Enterprise Linux 6
Red HatRed Hat Enterprise Linux 7
Red HatRed Hat Enterprise Linux 8
Red HatRed Hat Directory Server 13
Red HatRed Hat Directory Server 13.21788851765
Red HatRed Hat Enterprise Linux 90:2.8.0-10.el9_8
Red HatRed Hat Enterprise Linux 7
Red HatRed Hat Enterprise Linux 6
Red HatRed Hat Directory Server 12
Red HatRed Hat Enterprise Linux 8
Red HatRed Hat Enterprise Linux 100:3.2.0-10.el10_2
Red HatRed Hat Directory Server 11

Timeline

  • Aug 25, 2026 EPSS Score
  • Aug 25, 2026 Coalition ESS Score
  • Aug 25, 2026 CVE Published
  • Aug 27, 2026 EPSS Score
  • Sep 1, 2026 EPSS Score
  • Sep 3, 2026 Security Advisory
  • Sep 6, 2026 EPSS Score
  • Sep 8, 2026 EPSS Score
  • Sep 9, 2026 EPSS Score
  • Sep 9, 2026 Distribution Patch
  • Sep 9, 2026 Distribution Patch
  • Sep 9, 2026 Distribution Patch

References

Open in Interactive Console →
$ Console Community · 100/wk Open console ›