OpenLDAP is a foundational directory-services implementation widely embedded across enterprise authentication, authorization, and identity infrastructure, making it a prominent fixture in the vulnerability landscape despite a very narrow product footprint. Its vulnerability exposure concentrates in the core OpenLDAP server and library implementations and recurs through weakness classes including reachable assertions, double-free conditions, and improper certificate validation—patterns consistent with the protocol parsing and memory-management demands of a directory-services daemon. A moderate share of the vendor's disclosures acquire public exploit code, reflecting the infrastructure-critical nature of the software and the accessibility of its deployment environments. Defenders should prioritize this vendor's updates for production directory services and test-validate patches before deployment, as disruptions to LDAP authentication can cascade widely; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Openldap over time
Signals from CVEs in this vendor scope (62 CVEs).
62 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-36221HIGH An integer underflow was discovered in OpenLDAP before 2.4.57 leading to slapd crashes in the Certificate Exact Assertion processing, resulting in denial of service (schema_init.c | Jan 26, 2021 | 7.5 | 70 | NO | NO |
CVE-2022-29155CRITICAL In OpenLDAP 2.x before 2.5.12 and 2.6.x before 2.6.2, a SQL injection vulnerability exists in the experimental back-sql backend to slapd, via a SQL statement within an LDAP query. | May 4, 2022 | 9.8 | 68 | NO | NO |
CVE-2020-36227HIGH A flaw was discovered in OpenLDAP before 2.4.57 leading to an infinite loop in slapd with the cancel_extop Cancel operation, resulting in denial of service. | Jan 26, 2021 | 7.5 | 67 | NO | NO |
CVE-2020-36222HIGH A flaw was discovered in OpenLDAP before 2.4.57 leading to an assertion failure in slapd in the saslAuthzTo validation, resulting in denial of service. | Jan 26, 2021 | 7.5 | 67 | NO | NO |
CVE-2020-36228HIGH An integer underflow was discovered in OpenLDAP before 2.4.57 leading to a slapd crash in the Certificate List Exact Assertion processing, resulting in denial of service. | Jan 26, 2021 | 7.5 | 65 | NO | NO |
CVE-2006-5779HIGH OpenLDAP before 2.3.29 allows remote attackers to cause a denial of service (daemon crash) via LDAP BIND requests with long authcid names, which triggers an assertion failure. | Nov 7, 2006 | 7.5 | 61 | NO | NO |
CVE-2021-27212HIGH In OpenLDAP through 2.4.57 and 2.5.x through 2.5.1alpha, an assertion failure in slapd can occur in the issuerAndThisUpdateCheck function via a crafted packet, resulting in a denia | Feb 14, 2021 | 7.5 | 58 | NO | NO |
CVE-2010-0211CRITICAL The slap_modrdn2mods function in modrdn.c in OpenLDAP 2.4.22 does not check the return value of a call to the smr_normalize function, which allows remote attackers to cause a denia | Jul 28, 2010 | 9.8 | 56 | NO | YES |
CVE-2011-1081MEDIUM modrdn.c in slapd in OpenLDAP 2.4.x before 2.4.24 allows remote attackers to cause a denial of service (daemon crash) via a relative Distinguished Name (DN) modification request (a | Mar 20, 2011 | 5.0 | 32 | NO | YES |
CVE-2015-6908MEDIUM The ber_get_next function in libraries/liblber/io.c in OpenLDAP 2.4.42 and earlier allows remote attackers to cause a denial of service (reachable assertion and application crash) | Sep 11, 2015 | 5.0 | 31 | NO | YES |
Signals from CVEs in this vendor scope (62 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Openldap.
Media articles that mention a CVE ID that affects a product developed by Openldap — matched by CVE ID, not by vendor name.