CVE-2026-11787
MEDIUM
NVD
CVSS Score
5
Severity
MEDIUM
Published
Jun 09, 2026
Vendor
unknown
Description
A flaw was found in 389 Directory Server. The ldap_utf8prev() function reads bytes before the start of a buffer without bounds checking, causing a heap buffer over-read in string filter parsing that may influence internal filter processing behavior.