๐Ÿ” CVE Alert

CVE-2026-102731

UNKNOWN 0.0

Apache Directory LDAP API: Denial of service via excessive memory allocation in BER decode

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Memory allocation with excessive size value vulnerability in Apache Directory LDAP API. A malicious peer (or a MITM) can send a small BER-encoded response causing a large memory allocation before any data is received. This can lead to an OutOfMemoryError and denial of service. The client JVM OOMs (OutOfMemoryError bypasses the DecoderException handlers) or pins the large allocation per connection while the attacker stalls. A handful of connections exhausts any heap. The same bytes from an unauthenticated pre-bind client hit any embedding server that did not set MAX_PDU_SIZE_ATTR. This issue affects Apache Directory LDAP API: from 1.2.0 before 1.2.9. Users are recommended to upgrade to version 1.2.9, which fixes the issue.

CWE CWE-789
Vendor apache software foundation
Product apache directory ldap api
Published Oct 2, 2026
Stay Ahead of the Next One

Get instant alerts for apache software foundation apache directory ldap api

Be the first to know when new unknown vulnerabilities affecting apache software foundation apache directory ldap api are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Apache Software Foundation / Apache Directory LDAP API
1.2.0 < 1.2.9

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
lists.apache.org: https://lists.apache.org/thread.html/b8kg8881pc0v8lp59w0fcfrs69wjbqvd

Credits

Claude Security The Apache Software Foundation