Out of Bounds Read Vulnerability in Apache YuniKorn with LDAP Group Resolver
CVE-2026-78243

2.1LOW

Key Information:

Vendor

Apache

Vendor
CVE Published:
7 October 2026

What is CVE-2026-78243?

Apache YuniKorn versions 1.8.0 and later exhibit an out of bounds read vulnerability when configured to utilize the LDAP group resolver. This issue arises specifically when the LDAP server, in response to a user's pod, provides a memberOf attribute referencing a group membership entry that does not begin with 'CN='. In such cases, the YuniKorn service may crash unexpectedly. It is crucial to note that this vulnerability only impacts installations where the non-default LDAP group provider is utilized. Users are strongly advised to upgrade to Apache YuniKorn version 1.10.0 or later to mitigate this issue.

Affected Version(s)

Apache YuniKorn 1.8.0 < 1.10.0

References

CVSS V4

Score:
2.1
Severity:
LOW
Confidentiality:
None
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

gjoko@zeroscience.mk
.