Skip to main content

CVE-2026-22185

CVE Details​

Visit the official vulnerability details page for CVE-2026-22185 to learn more.

Initial Publication​

01/07/2026

Last Update​

06/17/2026

Third Party Dependency​

openldap

NIST CVE Summary​

OpenLDAP Lightning Memory-Mapped Database (LMDB) versions up to and including 0.9.14, prior to commit 8e1fda8, contain a heap buffer underflow in the readline() function of mdb_load. When processing malformed input containing an embedded NUL byte, an unsigned offset calculation can underflow and cause an out-of-bounds read of one byte before the allocated heap buffer. This can cause mdb_load to crash, leading to a limited denial-of-service condition.

CVE Severity​

4.6

Our Official Summary​

Investigation is ongoing to determine how this vulnerability affects our products.

Status​

Deferred

Affected Products & Versions​

VersionPaletteAIPaletteAI VerteX
1.4.0⚠️ Impacted⚠️ Impacted
1.3.2⚠️ Impacted⚠️ Impacted
1.2.2⚠️ Impacted⚠️ Impacted

Revision History​

No revisions available.