high · CVSS v3 7.5
CVE-2026-86344
CVE-2026-86344 is a high‑severity denial‑of‑service flaw in 389‑ds‑base that allows an unauthenticated attacker to exhaust the server’s work
Overview
CVE-2026-86344 is a high‑severity denial‑of‑service flaw in 389‑ds‑base that allows an unauthenticated attacker to exhaust the server’s worker thread pool by sending crafted LDAP messages. The attack blocks all LDAP connections, affecting both anonymous and authenticated clients over plain or TLS connections. It can be sustained as long as the attacker keeps the malicious connections open.
Description
A flaw was found in 389-ds-base. An unauthenticated remote attacker can send a complete LDAP operation followed by the first bytes of an incomplete LDAPMessage on the same connection, causing the server to hand that connection to a second worker thread before the first worker's result is flushed. The second worker blocks until nsslapd-ioblocktimeout while holding the connection mutex, preventing delivery of the completed operation's result. Repeating this across a small number of connections proportional to the configured worker-thread pool size exhausts the entire pool under default configuration, denying service to all clients (anonymous and authenticated, plaintext and TLS) for as long as the attacker maintains the connections.
Impact
The vulnerability causes a loss of availability for all LDAP clients, including applications and services that rely on directory authentication. Both anonymous and authenticated users are denied service, and the impact spans plaintext and TLS connections. The attack does not compromise confidentiality or integrity, but it disrupts normal operations.
Remediation
Apply the vendor‑supplied patch or upgrade to the latest 389‑ds‑base release that fixes the thread‑pool exhaustion issue. If an immediate upgrade is not possible, reduce the worker‑thread pool size (e.g., nsslapd-workerthreadpoolsize) and increase nsslapd‑ioblocktimeout to mitigate blocking. Additionally, enforce connection limits or rate‑limit incoming LDAP traffic to prevent abuse.
Risk context
The flaw is rated high with a CVSS v3 score of 7.5. No EPSS data is available, but the attack can be executed remotely without authentication, making it a significant risk for exposed LDAP services.
Affected products
- 389-ds-base
Scores
- Severity
- high
- CVSS v2
- 7.8
- CVSS v3
- 7.5
- CVSS v4
- —
- EPSS
- —