
🚨*CVE* CVE-2026-15041 A flaw was found in 389 Directory Server. The PBKDF2-SHA256 password verification function uses standard memcmp() for comparing password hashes instead of a constant-… https://www.cve.org/CVERecord?id=CVE-2026-15041 ----- Traducción: Se encontró una fa… http://infoflow.cloud`
Post summary
The post discloses CVE-2026-15041, a timing‑attack vulnerability in 389 Directory Server due to the use of memcmp() for password hash comparison.

