Hi,
The following vulnerabilities were published for apache-directory-api.
CVE-2026-102731[0]:
| Memory allocation with excessive size value vulnerability in Apache
| Directory LDAP API. A malicious peer (or a MITM) can send a small
| BER-encoded response causing a large memory allocation before any
| data is received. This can lead to an OutOfMemoryError and denial of
| service. The client JVM OOMs (OutOfMemoryError bypasses the
| DecoderException handlers) or pins the large allocation per
| connection while the attacker stalls. A handful of connections
| exhausts any heap. The same bytes from an unauthenticated pre-bind
| client hit any embedding server that did not set MAX_PDU_SIZE_ATTR.
| This issue affects Apache Directory LDAP API: from 1.2.0 before
| 1.2.9. Users are recommended to upgrade to version 1.2.9, which
| fixes the issue.
CVE-2026-103552[1]:
| Stack Overflow vulnerability in Apache Directory LDAP API. Before
| binding, a client can send a deeply nested search filter that
| overflows the stack in the server's decoder. This issue affects
| Apache Directory LDAP API: from 1.2.0 before 1.2.9. Users are
| recommended to upgrade to version 1.2.9, which fixes the issue.
CVE-2026-103877[2]:
| Deserialization of Untrusted Data vulnerability in Apache Directory
| LDAP API. A rogue/compromised LDAP server (or pre-TLS MITM) can
| answer a client's loadSchema() subschema search with a schema object
| that contains a serialized Java class, allowing some potential RCE.
| This issue affects Apache Directory LDAP API: from 2.1.0 before
| 2.1.9. Users are recommended to upgrade to version 2.1.9, which
| fixes the issue.
CVE-2026-103878[3]:
| Cleartext transmission of sensitive information vulnerability in
| Apache Directory LDAP API. A StartTLS extended operation started
| after a Search request has been sent can lead to receive data in
| plain text before the TLS Handshake has been completed. This
| issue affects Apache Directory LDAP API: from 2.1.0 before 2.1.9.
| Users are recommended to upgrade to version 2.1.9, which fixes the
| issue.
CVE-2026-103880[4]:
| Asymmetric Resource Consumption vulnerability in Apache Directory
| LDAP API. Storing a password using the bcrypt algorithm with a
| high force like 30 in a LDAP server that supports this algorithm
| will cause the server CPU to run for hours checking the
| credentials. A bounded cost should be enforced to avoid a server
| DOS. This issue affects Apache Directory LDAP API: from 2.1.0
| before 2.1.9. Users are recommended to upgrade to version 2.1.9,
| which fixes the issue.
CVE-2026-103885[5]:
| Asymmetric Resource Consumption vulnerability in Apache Directory
| LDAP API. A LDAP server using the LDAP API (like Apache DS) may
| consume 100% of a CPU core indefinitely when processing some badly
| crafted Telephone Numbers. This issue affects Apache Directory
| LDAP API: from 2.1.0 before 2.1.9. Users are recommended to
| upgrade to version 2.1.9, which fixes the issue.
If you fix the vulnerabilities please also make sure to include the
CVE (Common Vulnerabilities & Exposures) ids in your changelog entry.
For further information see:
[0] https://security-tracker.debian.org/tracker/CVE-2026-102731
https://www.cve.org/CVERecord?id=CVE-2026-102731
[1] https://security-tracker.debian.org/tracker/CVE-2026-103552
https://www.cve.org/CVERecord?id=CVE-2026-103552
[2] https://security-tracker.debian.org/tracker/CVE-2026-103877
https://www.cve.org/CVERecord?id=CVE-2026-103877
[3] https://security-tracker.debian.org/tracker/CVE-2026-103878
https://www.cve.org/CVERecord?id=CVE-2026-103878
[4] https://security-tracker.debian.org/tracker/CVE-2026-103880
https://www.cve.org/CVERecord?id=CVE-2026-103880
[5] https://security-tracker.debian.org/tracker/CVE-2026-103885
https://www.cve.org/CVERecord?id=CVE-2026-103885
Please adjust the affected versions in the BTS as needed.
Regards,
Salvatore