Asymmetric Resource Consumption Vulnerability in Apache Directory LDAP API by Apache
CVE-2026-103885

Currently unrated

Key Information:

Vendor

Apache

Vendor
CVE Published:
2 October 2026

What is CVE-2026-103885?

An asymmetric resource consumption vulnerability has been identified in the Apache Directory LDAP API that can lead to excessive CPU usage. Specifically, when an LDAP server, such as Apache DS, processes malformed telephone numbers, it may consume 100% of a CPU core indefinitely. This issue affects several versions of the Apache Directory LDAP API before 2.1.9. It is imperative for users to upgrade to version 2.1.9 to mitigate this vulnerability and ensure optimal performance.

Affected Version(s)

Apache Directory LDAP API 2.1.0 < 2.1.9

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Claude Security
The Apache Software Foundation
.