CVE-2026-78701
Received Received - Intake

SASL UNBIND DoS in 389 Directory Server

Vulnerability report for CVE-2026-78701, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-25

Last updated on: 2026-08-25

Assigner: redhat-SADP

Description

A flaw was found in 389-ds-base. A remote, authenticated attacker could exploit a vulnerability in the Simple Authentication and Security Layer (SASL) UNBIND process. By sending a specially crafted request, the attacker can cause a connection to stall, leading to resource exhaustion and a Denial of Service (DoS) for the server.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-25
Last Modified
2026-08-25
Generated
2026-08-25
AI Q&A
2026-08-25
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
redhat 389-ds-base *
red_hat 389-ds-base *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-787 The product writes data past the end, or before the beginning, of the intended buffer.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects 389-ds-base, an LDAP server. It involves a flaw in the SASL UNBIND process where a remote authenticated attacker can send a specially crafted request to stall a connection. This leads to resource exhaustion and a Denial of Service (DoS) for the server.

Detection Guidance

Monitor 389-ds-base service logs for stalled connections or resource exhaustion events. Check for repeated SASL UNBIND requests larger than the default 512-byte buffer. Use network monitoring tools like tcpdump to capture LDAP traffic and identify malformed UNBIND requests.

Impact Analysis

The vulnerability allows an authenticated attacker to cause a server to stall by sending oversized UNBIND requests. This exhausts server resources, leading to a DoS condition. The attack requires authentication, so only authorized users can exploit it.

Compliance Impact

This vulnerability could impact compliance with GDPR and HIPAA by enabling denial-of-service attacks that disrupt LDAP server availability. Resource exhaustion from stalled connections may lead to unauthorized access or service disruptions, violating availability requirements in these regulations.

Mitigation Strategies

Restrict network access to 389-ds-base using firewall rules to allow only trusted IP addresses or subnets. Limit inbound connections to LDAP ports 389 and 636. Consider upgrading to a patched version of 389-ds-base if available.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-78701. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart