Junglewise Threat Intelligence

OpenIdentityPlatform OpenDJ SSRF and DoS in DSMLv2 gateway

Severity: critical · CVSS 9.4 · Published 2026-07-24

Vendors: Maven.

Executive brief

OpenDJ's DSMLv2 gateway, which allows applications to interact with directory services using web protocols, contains a critical security flaw. An unauthenticated attacker can exploit this to access sensitive internal files, probe private network services, or crash the server by exhausting its memory. This could lead to the theft of configuration data or a total service outage.

Technical details

The DSMLv2 SOAP gateway (opendj-dsml-servlet) in OpenDJ through 5.1.1 fails to validate xsd:anyURI values in DSML add/modify requests. Because the component dereferences these URIs without a scheme allowlist or egress filtering, a remote unauthenticated attacker can perform SSRF against internal endpoints (including cloud metadata), read local system files via the file:// scheme, or trigger a Denial of Service (DoS) by pointing the gateway to an unbounded data source that exhausts heap memory. Version 5.1.2 fixes these issues by disabling URI dereferencing by default, implementing a strict http/https allowlist, blocking reserved/loopback IP ranges, and enforcing authentication for the gateway.

Affected products

  • OpenIdentityPlatform OpenDJ (opendj-dsml-servlet) <= 5.1.1

Timeline

  • 2026-07-23: disclosed
  • 2026-07-24: advisory: GitHub Advisory published
  • 2026-07-24: patched: Fixed in version 5.1.2

References

Related threats