Denial of Service Vulnerability in 389-ds-base (CVE-2026-86344)
CVE-2026-86344 is a denial-of-service vulnerability in 389-ds-base where an unauthenticated remote attacker can exhaust the server thread pool by sending malformed LDAP messages.
CVE search metadata
CVE search record: CVE-2026-86344. Severity: high. CVSS: 7.5. KEV: no. Product: 389-ds-base. Brief: Denial of Service Vulnerability in 389-ds-base (CVE-2026-86344). Brief link: https://feed.craftedsignal.io/briefs/2026-10-389-ds-base-dos/
What's new
- 1. added coverage for 389-ds-base Oct 2, 00:19 via nvd
CVE-2026-86344 is a critical denial-of-service vulnerability affecting 389-ds-base, a popular LDAP server. An unauthenticated remote attacker can exploit the connection handling logic by sending a complete LDAP operation immediately followed by the initial bytes of an incomplete LDAPMessage on the same connection. This interaction causes a race condition where the server hands the connection to a second worker thread before the first worker flushes its results. The second worker thread then blocks while waiting for the remainder of the incomplete message while holding a connection mutex. By repeating this process across multiple connections, an attacker can exhaust the worker-thread pool, effectively halting service for all clients, including those using plaintext or TLS connections, for the duration of the established connections.
Impact
Successful exploitation results in a complete denial of service for the target 389 Directory Server instance. The attack is highly effective as it requires only a small number of connections proportional to the configured worker-thread pool size to cause a total service outage. This impacts any environment relying on 389-ds-base for identity management, authentication, or directory services.
Recommendation
Prioritized actions for administrators and security teams:
- Review 389-ds-base deployment configurations to identify potentially exposed LDAP interfaces.
- Implement network-level rate limiting for LDAP traffic (port 389/636) to mitigate the impact of connection-heavy exhaustion attacks.
- Monitor logs for unusual patterns of incomplete or malformed LDAP messages if application-level logging is available.
- Apply vendor-provided patches for CVE-2026-86344 immediately upon release.
Immediate actions
Patch 389-ds-base to address CVE-2026-86344