CVE-2026-86345 - 389-ds-base: 389-ds-base: starttls plaintext-buffer retention allows on-path attacker to forge an ldap client's authentication result
CVE ID :CVE-2026-86345 Published : Oct. 2, 2026, 12:17 a.m. | 1 hour, 2 minutes ago Description :A flaw was found in 389-ds-base. The server does not discard plaintext bytes already buffered from a client connection when negotiating StartTLS, allowing an on-path attacker to inject a crafted...