Apache Directory LDAP API

6 known vulnerabilities in Apache Directory LDAP API, with patch priority, exploit likelihood and the news covering them.

Latest vulnerabilities

  • CVE-2026-103885 not yet scored Asymmetric Resource Consumption vulnerability in Apache Directory LDAP API. A LDAP server using the LDAP API (like Apache DS) may consume…
  • CVE-2026-103880 CVSS 7.5 high Asymmetric Resource Consumption vulnerability in Apache Directory LDAP API. Storing a password using the bcrypt algorithm with a high…
  • CVE-2026-103878 CVSS 7.5 high Cleartext transmission of sensitive information vulnerability in Apache Directory LDAP API. A StartTLS extended operation started after a…
  • CVE-2026-103877 not yet scored Deserialization of Untrusted Data vulnerability in Apache Directory LDAP API. A rogue/compromised LDAP server (or pre-TLS MITM) can answer…
  • CVE-2026-103552 CVSS 7.3 high Stack Overflow vulnerability in Apache Directory LDAP API. Before binding, a client can send a deeply nested search filter that overflows…
  • CVE-2026-102731 CVSS 7.5 high Memory allocation with excessive size value vulnerability in Apache Directory LDAP API. A malicious peer (or a MITM) can send a small…