Stack Overflow Vulnerability in Apache Directory LDAP API by Apache
CVE-2026-103552

Currently unrated

Key Information:

Vendor

Apache

Vendor
CVE Published:
2 October 2026

What is CVE-2026-103552?

The Apache Directory LDAP API is susceptible to a stack overflow vulnerability due to the handling of deeply nested search filters sent by clients before binding. This flaw can lead to a stack overflow in the server's decoder, potentially allowing an attacker to exploit the vulnerability. Users are advised to upgrade to version 1.2.9 to mitigate this risk, as it addresses the identified issue.

Affected Version(s)

Apache Directory LDAP API 1.2.0 < 1.2.9

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Claude Security
The Apache Software Foundation
.