Memory Allocation Vulnerability in Apache Directory LDAP API by Apache
CVE-2026-102731

Currently unrated

Key Information:

Vendor

Apache

Vendor
CVE Published:
2 October 2026

What is CVE-2026-102731?

A memory allocation vulnerability exists in Apache Directory LDAP API, where a malicious peer can exploit a BER-encoded response to trigger excessive memory allocation before any data is processed. This could lead to an OutOfMemoryError, causing denial of service, as the client JVM becomes overwhelmed. Attackers can stall connections, leading to further resource exhaustion. It is crucial for users of versions prior to 1.2.9 to upgrade to mitigate these risks.

Affected Version(s)

Apache Directory LDAP API 1.2.0 < 1.2.9

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Claude Security
The Apache Software Foundation
.