Security: OpenIdentityPlatform/OpenDJ
Security Advisories
View known security vulnerabilities and report new vulnerabilities privately to maintainers.
-
OpenDJ SASL PLAIN authzid bypassing the proxy ACI scope checkGHSA-p279-2cqp-84jg published
Jul 23, 2026 by vharsekoCritical -
OpenDJ unauthenticated SSRF, local file read and unbounded-read DoS in the DSMLv2 gatewayGHSA-68r5-9hpg-7qw9 published
Jul 23, 2026 by vharsekoCritical -
OpenDJ Unbounded VLV offset array allocation → memory-exhaustion DoSGHSA-q4wx-wj4j-4657 published
Jul 22, 2026 by vharsekoHigh -
OpenDJ JMX MBean-argument deserialization without a serial filterGHSA-qj63-3vrg-vcfx published
Jul 22, 2026 by vharsekoModerate -
OpenDJ Unauthenticated stack exhaustion when decoding an LDAP search filter (DoS)GHSA-rv4q-c6mr-wxp7 published
Jul 21, 2026 by vharsekoHigh -
OpenDJ Unauthenticated RCE via Java Deserialization in JMX RMIGHSA-43x2-g84q-fmqx published
Jun 20, 2026 by vharsekoCritical -
OpenDJ Denial of Service (Dos) using alias loopGHSA-93qr-h8pr-4593 published
Mar 5, 2025 by vharsekoHigh