Virtual attribute handling in Ping Identity PingDirectory in affected versions allows only authorized users to exhaust java memory heap when recent login history is enabled and copying virtual attributes that reference ds-privilege-name values.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Fri, 12 Jun 2026 04:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Pingidentity
Pingidentity pingdirectory |
|
| Vendors & Products |
Pingidentity
Pingidentity pingdirectory |
Fri, 12 Jun 2026 03:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Virtual attribute handling in Ping Identity PingDirectory in affected versions allows only authorized users to exhaust java memory heap when recent login history is enabled and copying virtual attributes that reference ds-privilege-name values. | |
| Title | PingDirectory copying of virtual attributes leads to memory exhaustion | |
| Weaknesses | CWE-401 | |
| References |
|
|
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: Ping Identity
Published:
Updated: 2026-06-12T02:16:59.690Z
Reserved: 2026-01-07T15:15:23.456Z
Link: CVE-2026-20746
No data.
Status : Received
Published: 2026-06-12T04:17:04.510
Modified: 2026-06-12T04:17:04.510
Link: CVE-2026-20746
No data.
OpenCVE Enrichment
Updated: 2026-06-12T05:00:17Z
Weaknesses