๐Ÿ” CVE Alert

CVE-2026-103552

UNKNOWN 0.0

Apache Directory LDAP API: A unbound client can send a deeply nested search filter that overflows the stack in the server's decoder

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Stack Overflow vulnerability in Apache Directory LDAP API. Before binding, a client can send a deeply nested search filter that overflows the stack in the server's decoder. This issue affects Apache Directory LDAP API: from 1.2.0 before 1.2.9. Users are recommended to upgrade to version 1.2.9, which fixes the issue.

CWE CWE-121
Vendor apache software foundation
Product apache directory ldap api
Published Oct 2, 2026
Stay Ahead of the Next One

Get instant alerts for apache software foundation apache directory ldap api

Be the first to know when new unknown vulnerabilities affecting apache software foundation apache directory ldap api are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Apache Software Foundation / Apache Directory LDAP API
1.2.0 < 1.2.9

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
lists.apache.org: https://lists.apache.org/thread.html/fn3bwknn57266hx66w9vv6b4k8rfwcx7

Credits

Claude Security The Apache Software Foundation