Memory Allocation Vulnerability in Apache Directory LDAP API by Apache
CVE-2026-102731
Currently unrated
What is CVE-2026-102731?
A memory allocation vulnerability exists in Apache Directory LDAP API, where a malicious peer can exploit a BER-encoded response to trigger excessive memory allocation before any data is processed. This could lead to an OutOfMemoryError, causing denial of service, as the client JVM becomes overwhelmed. Attackers can stall connections, leading to further resource exhaustion. It is crucial for users of versions prior to 1.2.9 to upgrade to mitigate these risks.
Affected Version(s)
Apache Directory LDAP API 1.2.0 < 1.2.9