Skip to content
CVE-2026-86344: Denial-of-Service Vulnerability in Red Hat Directory Server

CVE-2026-86344: Denial-of-Service Vulnerability in Red Hat Directory Server

First seen 2 Oct 2026, 06:02 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •October 2, 2026 at 06:03 UTC
  • •CVE-2026-86344 affects Red Hat Directory Server's 389-ds-base.
  • •Unauthenticated attackers can exploit the flaw to cause denial-of-service.
  • •No active exploitation has been confirmed; however, systems should be monitored.

A flaw in 389-ds-base allows unauthenticated remote attackers to exhaust the worker-thread pool, denying service to all clients. The vulnerability can be exploited by sending a complete LDAP operation followed by incomplete LDAPMessage bytes on the same connection. This results in blocking the connection mutex and preventing the delivery of completed operations. The attack can be sustained as long as the attacker maintains a small number of connections. Systems that are internet-accessible are at the highest risk, particularly those serving identity functions. The flaw does not affect data confidentiality or integrity, and normal service resumes quickly after the attack ends. As of now, no active exploitation has been confirmed, and the likelihood of exploitation remains uncertain. Administrators are advised to apply vendor patches promptly and limit concurrent LDAP connections from a single source IP.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-10-01
CVE-2026-86344 published
The vulnerability was officially published with a CVSS score of 7.5, indicating high severity.
access.redhat.com
2026-10-02
CVE-2026-86344 reported
Redpacketsecurity reported on the vulnerability, emphasizing the risk to services accessible over untrusted networks.
Redpacketsecurity

More articles in this cluster (2)

Following this threat?

Track Red Hat and CVE-2026-86344 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed

Common questions

What systems are affected?
The vulnerability affects Red Hat Directory Server's 389-ds-base, particularly in default configurations.
How can I mitigate this vulnerability?
Apply the vendor's patches promptly and consider limiting concurrent LDAP connections from a single source IP.
Is there any active exploitation of this CVE?
Currently, there is no confirmed active exploitation of CVE-2026-86344.