Asymmetric Resource Consumption Vulnerability in Apache Directory LDAP API
CVE-2026-103880
Currently unrated
What is CVE-2026-103880?
The Apache Directory LDAP API is susceptible to an asymmetric resource consumption vulnerability. When passwords are stored using the bcrypt algorithm with an excessive cost factor, specifically set to 30, the server's CPU could be overwhelmed while validating credentials, potentially leading to a denial of service. To mitigate this risk, it is crucial to impose a bounded cost limit on password hashing. Users are advised to update to version 2.1.9 or later, which addresses this concern effectively.
Affected Version(s)
Apache Directory LDAP API 2.1.0 < 2.1.9