EIP-2026-102706

PRE-CVE

OpenLDAP 2.2.29 - Remote Denial of Service (Metasploit)

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-102706. PoCs published by Evgeny Legerov.

AI-analyzed exploit summary This is a Denial of Service (DoS) exploit for OpenLDAP, targeting a vulnerability in the `ldap_dn2bv_x` function. It sends malformed LDAP BIND requests to trigger an assertion failure, causing the OpenLDAP server to crash.

Description

OpenLDAP 2.2.29 - Remote Denial of Service (Metasploit)

Exploits (1)

exploitdb WORKING POC VERIFIED
by Evgeny Legerov · doslinux
https://www.exploit-db.com/exploits/2730

This is a Denial of Service (DoS) exploit for OpenLDAP, targeting a vulnerability in the `ldap_dn2bv_x` function. It sends malformed LDAP BIND requests to trigger an assertion failure, causing the OpenLDAP server to crash.

Classification
Working Poc 95%
Attack Type
Dos
Complexity
Trivial
Reliability
Reliable
Target: OpenLDAP 2.2.29-1.FC4.i386.rpm / Fedora Core 4
No auth needed
Prerequisites: Network access to the target OpenLDAP server on port 389
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026