{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/tags/directory-services/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:389:389_directory_server:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.5,"id":"CVE-2026-86344"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["389-ds-base"],"_cs_severities":["high"],"_cs_tags":["ldap","authentication-bypass","directory-services"],"_cs_type":"advisory","_cs_vendors":["389 Directory Server"],"content_html":"\u003cp\u003eCVE-2026-86344 is a critical denial-of-service vulnerability affecting 389-ds-base, a popular LDAP server. An unauthenticated remote attacker can exploit the connection handling logic by sending a complete LDAP operation immediately followed by the initial bytes of an incomplete LDAPMessage on the same connection. This interaction causes a race condition where the server hands the connection to a second worker thread before the first worker flushes its results. The second worker thread then blocks while waiting for the remainder of the incomplete message while holding a connection mutex. By repeating this process across multiple connections, an attacker can exhaust the worker-thread pool, effectively halting service for all clients, including those using plaintext or TLS connections, for the duration of the established connections.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation results in a complete denial of service for the target 389 Directory Server instance. The attack is highly effective as it requires only a small number of connections proportional to the configured worker-thread pool size to cause a total service outage. This impacts any environment relying on 389-ds-base for identity management, authentication, or directory services.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritized actions for administrators and security teams:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eReview 389-ds-base deployment configurations to identify potentially exposed LDAP interfaces.\u003c/li\u003e\n\u003cli\u003eImplement network-level rate limiting for LDAP traffic (port 389/636) to mitigate the impact of connection-heavy exhaustion attacks.\u003c/li\u003e\n\u003cli\u003eMonitor logs for unusual patterns of incomplete or malformed LDAP messages if application-level logging is available.\u003c/li\u003e\n\u003cli\u003eApply vendor-provided patches for CVE-2026-86344 immediately upon release.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-10-02T00:19:50Z","date_published":"2026-10-01T22:18:44Z","id":"https://feed.craftedsignal.io/briefs/2026-10-389-ds-base-dos/","summary":"CVE-2026-86344 is a denial-of-service vulnerability in 389-ds-base where an unauthenticated remote attacker can exhaust the server thread pool by sending malformed LDAP messages.","title":"Denial of Service Vulnerability in 389-ds-base (CVE-2026-86344)","url":"https://feed.craftedsignal.io/briefs/2026-10-389-ds-base-dos/"}],"language":"en","title":"CraftedSignal Threat Feed - Directory-Services","version":"https://jsonfeed.org/version/1.1"}