ZeroHour

CVE-2026-11785

CVSS 3.1
4.3 medium
EPSS
<1%p8
Published
()
Modified
Description

A flaw was found in 389 Directory Server. A type confusion in the SSO token extended operation handler causes partial stack address information to be disclosed in LDAP responses to authenticated users.

Vendors
redhat
Products
directory server, 389 directory server, enterprise linux
Weakness
CWE-843
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

In the news

No ingested article mentions this CVE yet.