🔐 CVE Alert

CVE-2026-103878

UNKNOWN 0.0

Apache Directory LDAP API: Injection of plaintext responses during StartTLS

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Cleartext transmission of sensitive information vulnerability in Apache Directory LDAP API. A StartTLS extended operation started after a Search request has been sent can lead to receive data in plain text before the TLS Handshake has been completed. This issue affects Apache Directory LDAP API: from 2.1.0 before 2.1.9. Users are recommended to upgrade to version 2.1.9, which fixes the issue.

CWE CWE-345
Vendor apache software foundation
Product apache directory ldap api
Published Oct 2, 2026
Stay Ahead of the Next One

Get instant alerts for apache software foundation apache directory ldap api

Be the first to know when new unknown vulnerabilities affecting apache software foundation apache directory ldap api are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

Affected Versions

Apache Software Foundation / Apache Directory LDAP API
2.1.0 < 2.1.9

References

NVD ↗ CVE.org ↗ EPSS Data ↗
lists.apache.org: https://lists.apache.org/thread.html/d98f9w01nd3zmkwrr21y0l9kdr9jpty9

Credits

Claude Security The Apache Software Foundation