{"id":"CVE-2025-27497","summary":"OpenDJ Denial of Service (Dos) using alias loop","details":"OpenDJ is an LDAPv3 compliant directory service. OpenDJ prior to 4.9.3 contains a denial-of-service (DoS) vulnerability that causes the server to become unresponsive to all LDAP requests without crashing or restarting. This issue occurs when an alias loop exists in the LDAP database. If an ldapsearch request is executed with alias dereferencing set to \"always\" on this alias entry, the server stops responding to all future requests. Fortunately, the server can be restarted without data corruption. This vulnerability is fixed in 4.9.3.","aliases":["GHSA-93qr-h8pr-4593"],"modified":"2026-08-12T14:52:36.805860Z","published":"2025-03-05T15:59:01.702Z","database_specific":{"cna_assigner":"GitHub_M","cwe_ids":["CWE-835"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/27xxx/CVE-2025-27497.json"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/27xxx/CVE-2025-27497.json"},{"type":"ADVISORY","url":"https://github.com/OpenIdentityPlatform/OpenDJ/security/advisories/GHSA-93qr-h8pr-4593"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-27497"},{"type":"FIX","url":"https://github.com/OpenIdentityPlatform/OpenDJ/commit/08aee4724608e4a32baa3c7d7499ec913a275aaf"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/openidentityplatform/opendj","events":[{"introduced":"0"},{"fixed":"08aee4724608e4a32baa3c7d7499ec913a275aaf"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"fixed":"4.9.3"}],"source":["AFFECTED_FIELD","REFERENCES"]}}],"versions":["4.9.2","4.9.1","4.9.0","4.8.2","4.8.1","4.8.0","4.7.0","4.6.5","4.6.4","4.6.3","4.6.2","4.6.1","4.5.9","4.5.6","4.5.5","4.5.4","4.5.3","4.5.1","4.5.0","4.4.15","4.4.14","4.4.13","4.4.12","4.4.11","4.4.10","4.4.9","4.4.8","4.4.7","4.4.6","4.4.5","4.4.4","4.4.3","4.4.2","4.4.1","4.3.5","4.3.4","4.3.3","4.3.2","4.3.1","4.2.5","4.2.4","4.2.3","4.2.2","4.2.1","4.1.10","4.1.9","4.1.6","4.0.3","4.0.2","4.0.1","4.0.0-M1","3.0.0-M7","3.0.0-M6","3.0.0-M5","3.0.0-M4","last-common-commit-with-opendj-sdk-repo"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-27497.json","vanir_signatures_modified":"2026-08-12T14:52:36Z","vanir_signatures":[{"id":"CVE-2025-27497-37824ebb","signature_type":"Line","signature_version":"v1","source":"https://github.com/openidentityplatform/opendj/commit/08aee4724608e4a32baa3c7d7499ec913a275aaf","target":{"file":"opendj-server-legacy/src/test/java/org/openidentityplatform/opendj/AliasTestCase.java"},"deprecated":false,"digest":{"line_hashes":["188018006673661304711444580092695442197","48453000323445208640862621998075702079","175103937662594734893618933112940898063","254991645756086597156582888158571659725","50223598449627683416406802193089993427","98377641471148069267817362694836291762","128808626856573400766701201809697077321","152151815260735817910589927277079012942","63562251532412664704716803128249902899","283439860792056333348857842727764560784","9879313759917733462801506721604249845","19154173803706057555853720780498964593","86763002906638808146026476758772866383","40086285168911220228920542458922438433","284252107701761353622355933713556163139","243465979369328391703162430414796031182","12075647454153107040238314914916288146"],"threshold":0.9}},{"id":"CVE-2025-27497-71bdb923","signature_type":"Function","signature_version":"v1","source":"https://github.com/openidentityplatform/opendj/commit/08aee4724608e4a32baa3c7d7499ec913a275aaf","target":{"file":"opendj-server-legacy/src/test/java/org/openidentityplatform/opendj/AliasTestCase.java","function":"search"},"deprecated":false,"digest":{"function_hash":"303497923321976179571845124423907217714","length":661}},{"target":{"file":"opendj-server-legacy/src/main/java/org/opends/server/workflowelement/localbackend/LocalBackendSearchOperation.java"},"deprecated":false,"digest":{"line_hashes":["269812013495336159954465064107135299508","166113159221378505773136104641035386500","180738057474646382112414112745195128666","238568921632766483849227079998983985675","216865163716120902537401480827352642479","335059483384539724956480238587617714821","213396218755930126395036285100277172723","176445711731140782570985030861759725297","309917880816691490762432974932878913902","280140758804966650925062296286485455218"],"threshold":0.9},"id":"CVE-2025-27497-988f018f","signature_type":"Line","signature_version":"v1","source":"https://github.com/openidentityplatform/opendj/commit/08aee4724608e4a32baa3c7d7499ec913a275aaf"},{"signature_version":"v1","source":"https://github.com/openidentityplatform/opendj/commit/08aee4724608e4a32baa3c7d7499ec913a275aaf","target":{"file":"opendj-server-legacy/src/main/java/org/opends/server/workflowelement/localbackend/LocalBackendSearchOperation.java","function":"processSearch"},"deprecated":false,"digest":{"function_hash":"316564709844541449187418425717076015032","length":2353},"id":"CVE-2025-27497-e748c403","signature_type":"Function"},{"target":{"file":"opendj-server-legacy/src/test/java/org/openidentityplatform/opendj/AliasTestCase.java","function":"startServer"},"deprecated":false,"digest":{"length":881,"function_hash":"211499179375251590318593159567050337660"},"id":"CVE-2025-27497-e9cc765f","signature_type":"Function","signature_version":"v1","source":"https://github.com/openidentityplatform/opendj/commit/08aee4724608e4a32baa3c7d7499ec913a275aaf"}]}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"}]}