Asymmetric Resource Consumption Vulnerability in Apache Directory LDAP API
CVE-2026-103880

Currently unrated

Key Information:

Vendor

Apache

Vendor
CVE Published:
2 October 2026

What is CVE-2026-103880?

The Apache Directory LDAP API is susceptible to an asymmetric resource consumption vulnerability. When passwords are stored using the bcrypt algorithm with an excessive cost factor, specifically set to 30, the server's CPU could be overwhelmed while validating credentials, potentially leading to a denial of service. To mitigate this risk, it is crucial to impose a bounded cost limit on password hashing. Users are advised to update to version 2.1.9 or later, which addresses this concern effectively.

Affected Version(s)

Apache Directory LDAP API 2.1.0 < 2.1.9

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Claude Security
The Apache Software Foundation
.