CVE-2026-18355 is a heap buffer overflow in the SASL I/O layer of 389 Directory Server (389-ds-base). In sasl_io_start_packet(), the wrapped-record length received from the peer is checked only against a maximum value. Lengths of 0, 1, or 2 cause the encrypted-buffer count to be smaller than an already consumed encrypted-buffer offset. sasl_io_read_packet() subsequently performs an unsigned subtraction that underflows and requests a read of approximately 4 GiB into a 1024-byte heap buffer. The received data is attacker controlled. This issue is distinct from CVE-2026-11774, whose fix addressed only an upper-bound condition.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
No public exploits tracked yet. Mallory keeps watching.
No public exploit code observed for this vulnerability.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A lower-bound underflow in SASL wrapped-record length processing in 389-ds-base sasl_io_start_packet() can cause a heap buffer overflow.
A heap buffer overflow in 389-ds-base sasl_io_start_packet() caused by lower-bound underflow in SASL wrapped-record length processing.
A heap buffer overflow in 389-ds-base caused by lower-bound underflow in SASL wrapped-record length handling within sasl_io_start_packet().
A remotely triggerable, authenticated heap buffer overflow in the SASL I/O layer of 389 Directory Server (389-ds-base). Following a successful SASL bind with integrity protection enabled (SSF > 0), malformed small wrapped-record lengths can cause an integer underflow and attacker-controlled heap overflow, resulting in denial of service or potential remote code execution.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.