What is CVE-2026-18663?
A critical vulnerability has been found in 389-ds-base directory server. A double-free flaw exists in the get_ldapmessage_controls_ext() function, which could allow an unauthenticated remote attacker to cause a Denial of Service. Affected systems should immediately apply the security update released by the vendor.
Azərbaycanca: 389-ds-base direktoriya serverində kritik zəiflik aşkarlanıb. get_ldapmessage_controls_ext() funksiyasında "double-free" xətası mövcuddur ki, bu da uzaqdan autentifikasiya olunmamış hücumçuya servisin dayanmasına (Denial of Service) səbəb ola bilər. Təsirə məruz qalan sistemlərdə təchizatçı tərəfindən buraxılmış təhlükəsizlik yeniləməsi dərhal tətbiq edilməlidir.
Related CVEs
link basis: same weakness class CWE-416
FAQ2
What software is affected by CVE-2026-18663?
The vulnerability affects the 389-ds-base directory server.
What can an attacker achieve by exploiting this vulnerability?
An unauthenticated remote attacker can cause a Denial of Service.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.