Red Hat Directory Server
Red Hat Directory Server is an LDAP-compliant server that centralizes user identity and application information. It provides an operating system-independent, network-based registry for storing application settings, user profiles, group data, policies, and access control information.
browse_doc
Red Hat Directory Server 13 release notesRelease Notes
Planning and designing Directory ServerPlanning, Installing and Upgrading
Installing Red Hat Directory ServerPlanning, Installing and Upgrading
Management, configuration, and operationsSystem administration
Configuring and managing replicationSystem administration
Configuration and schema referenceReference
latest_security
| severity | advisory_cve | synopsis | date |
|---|---|---|---|
| severity Important | advisory_cveCVE-2026-73643 | synopsis A flaw was found in js-yaml, a JavaScript YAML parser. A remote attacker could exploit this vulnerability by providing specially crafted YAML input containing nested flow collections. This can lead to exponential parsing time when the application processes untrusted input, consuming excessive CPU resources. This resource exhaustion can block the Node.js event loop and cause a Denial of Service (DoS) for the affected process. | date |
| severity Moderate | advisory_cveCVE-2026-18663 | synopsis A flaw was found in 389-ds-base. The get_ldapmessage_controls_ext() function frees the parsed controls array on the Session Tracking critical-control rejection path without clearing the SLAPI_REQCONTROLS pblock slot. Operation teardown then frees the same pointer again, causing a double-free. An unauthenticated remote attacker can trigger this with a single BIND request carrying a critical Session Tracking control, resulting in heap corruption and potential denial of service. | date |
| severity Moderate | advisory_cveCVE-2026-11770 | synopsis A flaw was found in 389 Directory Server. An unauthenticated remote attacker can inject LDAP search filters into the CleanAllRUV replication status-check extended operation. Because the handler performs the search against cn=config with elevated replication plugin privileges and returns a boolean match result, the attacker can extract sensitive server configuration metadata, including replication bind DNs and password storage scheme information. | date |
| severity Important | advisory_cveCVE-2026-15722 | synopsis A stack buffer overflow flaw was found in 389 Directory Server (389-ds-base). The get_ruvelement_from_berval() function in repl5_ruv.c copies digit characters from a network-supplied RUV berval into a fixed 16-byte stack buffer without bounds checking. A remote unauthenticated attacker can crash the LDAP server by sending a crafted StartNSDS50ReplicationRequest extended operation containing a replica ID field with more than 16 digit characters. The overflow occurs during payload decoding, before any authorization check. Stack protectors limit impact to denial of service. | date |
| severity Important | advisory_cve(RHSA-2026:36660) Red Hat Directory Server 13.2 container image update | synopsis Red Hat Directory Server 13.2 container image update | date |
top_resources
Knowledgebase
Access articles and solutions to find answers to your questions.
Troubleshooting
Connect to the right information to self-solve issues quickly and efficiently.
Lifecycle
View the various levels of maintenance for each release of a product over a period from initial release to the end of maintenance.
Release dates
Lists major and minor Red Hat Directory Server releases, their dates, errata and release notes links.