CVE-2026-102731: fallo de gravedad alta en Apache Directory LDAP API
Apache Directory LDAP API: Denial of service via excessive memory allocation in BER decode
Publicada el · Actualizada el
21Vexday Risk Score
Sin señal de explotación. Ningún artefacto público de explotación conocido hasta ahora.
ssvc Trackcvss 7.5epss 0.4%
probabilidad de explotación
0.4%top 65% de las CVE
explotación observada
noninguna fuente lo reporta
Memory allocation with excessive size value vulnerability in Apache Directory LDAP API.
A malicious peer (or a MITM) can send a small BER-encoded response causing a large memory allocation before any data is received. This can lead to an OutOfMemoryError and denial of service.
The client JVM OOMs (OutOfMemoryError bypasses the DecoderException handlers) or pins the large allocation per connection while the attacker stalls.
A handful of connections exhausts any heap. The same bytes from an unauthenticated pre-bind client hit any embedding server that did not set MAX_PDU_SIZE_ATTR.
This issue affects Apache Directory LDAP API: from 1.2.0 before 1.2.9.
Users are recommended to upgrade to version 1.2.9, which fixes the issue.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Productos afectados
Apache Software Foundation · Apache Directory LDAP APICVEs relacionadas — Apache Directory LDAP API
En el mismo producto, de las más peligrosas a las menos.
CVE-2026-103880HIGHApache Directory LDAP API: Denial of service via excessive bcrypt cost factor in stored passwordsEPSS 0.5%CVE-2026-103877CRITICALApache Directory LDAP API: Unsafe loading of Java code from LDAP schema elementsEPSS 0.4%CVE-2026-103552HIGHApache Directory LDAP API: A unbound client can send a deeply nested search filter that overflows the stack in the server's decoderEPSS 0.3%CVE-2026-35563HIGHApache Directory LDAP API: LDAP client implementation does not verify if the server certificate matches the intended LDAP hostnameEPSS 0.3%CVE-2026-103878HIGHApache Directory LDAP API: Injection of plaintext responses during StartTLSEPSS 0.2%CVE-2026-103885HIGHApache Directory LDAP API: Denial of service via crafted telephone number valuesEPSS 0.2%