Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2019-19906

29
FAUCET Score

CVE-2019-19906 describes an unauthenticated remote denial-of-service vulnerability in cyrus-sasl 2.1.27, affecting products like OpenLDAP, Apache, Apple, and Red Hat. This high-severity flaw (CVSS 7.5) stems from an off-by-one error leading to an out-of-bounds write, allowing attackers to crash services via a malformed LDAP packet without authentication. While no public exploit code or active exploitation has been observed, the vulnerability has garnered some community discussion, with a fix released in Cyrus SASL 2.1.28.

Impacted Technologies

VendorProductVersion(s)CPE
< 2.1.28CPE matchmatch criteria
cpe:2.3:a:cyrusimap:cyrus-sasl:*:*:*:*:*:*:*:*
8.0CPE matchmatch criteria
cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*
9.0CPE matchmatch criteria
cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*
10.0CPE matchmatch criteria
cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*
12.04CPE matchmatch criteria
cpe:2.3:o:canonical:ubuntu_linux:12.04:*:*:*:-:*:*:*

CVSS Data

CVSS version used by this source: 3.1

7.5HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
HIGH
Exploitability Score
3.9
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
8.04%
Probability of exploitation in next 30 days
EPSS Percentile
94.2%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0804 is in the 90th percentile among its peer group of 51,551 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (11)

github_advisorypatch availablevia nvd_reference
View patch
microsoftpatch availablevia msrc
Product: CBL Mariner 2.0 ARMFixed in: 2.1.27-10
microsoftpatch availablevia msrc
Product: CBL Mariner 1.0 ARMFixed in: 2.1.27-4
microsoftpatch availablevia msrc
Product: CBL Mariner 2.0 x64Fixed in: 2.1.27-10
microsoftpatch availablevia msrc
Product: cm1 cyrus-sasl 2.1.27-4 on CBL Mariner 1.0Fixed in: 2.1.27-4
microsoftpatch availablevia msrc
Product: cbl2 cyrus-sasl 2.1.27-10 on CBL Mariner 2.0Fixed in: 2.1.27-10
microsoftpatch availablevia msrc
Product: 17039-16820Fixed in: 2.1.27-4
microsoftpatch availablevia msrc
Product: 17040-16823Fixed in: 2.1.27-10
microsoftpatch availablevia msrc
Product: CBL Mariner 1.0 x64Fixed in: 2.1.27-4
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: cyrus-sasl-0:2.1.27-5.el8
View patch
redhatend of lifevia redhat_api
Product: Red Hat Enterprise Linux 7Fixed in: cyrus-sasl

Vendor Advisories (3)

microsoft2020-Aug/CVE-2019-19906

CVE-2019-19906

Aug 11, 2020
microsoft2019-Dec/CVE-2019-19906Important

cyrus-sasl (aka Cyrus SASL) 2.1.27 has an out-of-bounds write leading to unauthenticated remote denial-of-service in OpenLDAP via a malformed LDAP packet. The OpenLDAP crash is ultimately caused by an off-by-one error in _sasl_add_string in common.c in cyrus-sasl.

Dec 10, 2019
redhatCVE-2019-19906Moderate

cyrus-sasl: denial of service in _sasl_add_string function

Nov 28, 2019

References

seclists.org / fulldisclosure/2020/Jul/23
Mailing ListThird Party Advisory
seclists.org / fulldisclosure/2020/Jul/24
Mailing ListThird Party Advisory
github.com / cyrusimap/cyrus-sasl/issues/587
PatchThird Party Advisory
lists.apache.org / thread.html/r58af02e294bd07f487e2c64ffc0a29b837db5600e33b6e698b9d696b%40%3Cissues.bookkeeper.apache.org%3E
lists.apache.org / thread.html/rf4c02775860db415b4955778a131c2795223f61cb8c6a450893651e4%40%3Cissues.bookkeeper.apache.org%3E
lists.debian.org / debian-lts-announce/2019/12/msg00027.html
Mailing ListThird Party Advisory
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/MW6GZCLECGL2PBNHVNPJIX4RPVRVFR7R
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/OB4GSVOJ6ESHQNT5GSV63OX5D4KPSTGT
seclists.org / bugtraq/2019/Dec/42
Mailing ListThird Party Advisory
support.apple.com / kb/HT211288
Third Party Advisory
support.apple.com / kb/HT211289
Third Party Advisory
usn.ubuntu.com / 4256-1
PatchThird Party Advisory
debian.org / security/2019/dsa-4591
Third Party Advisory
openldap.org / its/index.cgi/Incoming
ExploitThird Party Advisory
openwall.com / lists/oss-security/2022/02/23/4
Mailing ListPatchRelease NotesThird Party Advisory