#1149877 apache-directory-api: CVE-2026-102731 CVE-2026-103552 CVE-2026-103877 CVE-2026-103878 CVE-2026-103880 CVE-2026-103885

Package:
src:apache-directory-api
Source:
src:apache-directory-api
Submitter:
Salvatore Bonaccorso
Date:
2026-10-03 21:01:05 UTC
Severity:
normal
Tags:
#1149877#5
Date:
2026-10-03 21:00:21 UTC
From:
To:
Hi,

The following vulnerabilities were published for apache-directory-api.

CVE-2026-102731[0]:
| Memory allocation with excessive size value vulnerability in Apache
| Directory LDAP API.    A malicious peer (or a MITM) can send a small
| BER-encoded response causing a large memory allocation before any
| data is received. This can lead to an OutOfMemoryError and denial of
| service.    The client JVM OOMs (OutOfMemoryError bypasses the
| DecoderException handlers) or pins the large allocation per
| connection while the attacker stalls.    A handful of connections
| exhausts any heap. The same bytes from an unauthenticated pre-bind
| client hit any embedding server that did not set MAX_PDU_SIZE_ATTR.
| This issue affects Apache Directory LDAP API: from 1.2.0 before
| 1.2.9.    Users are recommended to upgrade to version 1.2.9, which
| fixes the issue.


CVE-2026-103552[1]:
| Stack Overflow vulnerability in Apache Directory LDAP API.    Before
| binding, a client can send a deeply nested search filter that
| overflows the stack in the server's decoder.    This issue affects
| Apache Directory LDAP API: from 1.2.0 before 1.2.9.    Users are
| recommended to upgrade to version 1.2.9, which fixes the issue.


CVE-2026-103877[2]:
| Deserialization of Untrusted Data vulnerability in Apache Directory
| LDAP API.    A rogue/compromised LDAP server (or pre-TLS MITM) can
| answer a client's loadSchema() subschema search with a schema object
| that contains a serialized Java class, allowing some potential RCE. 
| This issue affects Apache Directory LDAP API: from 2.1.0 before
| 2.1.9.    Users are recommended to upgrade to version 2.1.9, which
| fixes the issue.


CVE-2026-103878[3]:
| Cleartext transmission of sensitive information vulnerability in
| Apache Directory LDAP API.    A StartTLS extended operation started
| after a Search request has been sent can lead to receive data in
| plain text before the TLS Handshake has been completed.    This
| issue affects Apache Directory LDAP API: from 2.1.0 before 2.1.9.
| Users are recommended to upgrade to version 2.1.9, which fixes the
| issue.


CVE-2026-103880[4]:
| Asymmetric Resource Consumption vulnerability in Apache Directory
| LDAP API.    Storing a password using the bcrypt algorithm with a
| high force like 30 in a LDAP server that supports this algorithm
| will cause the server CPU to  run for hours checking the
| credentials. A bounded cost should be enforced to avoid a server
| DOS.    This issue affects Apache Directory LDAP API: from 2.1.0
| before 2.1.9.    Users are recommended to upgrade to version 2.1.9,
| which fixes the issue.


CVE-2026-103885[5]:
| Asymmetric Resource Consumption vulnerability in Apache Directory
| LDAP API.    A LDAP server using the LDAP API (like Apache DS) may
| consume 100% of a CPU core indefinitely when processing some badly
| crafted Telephone Numbers.    This issue affects Apache Directory
| LDAP API: from 2.1.0 before 2.1.9.    Users are recommended to
| upgrade to version 2.1.9, which fixes the issue.


If you fix the vulnerabilities please also make sure to include the
CVE (Common Vulnerabilities & Exposures) ids in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-102731
https://www.cve.org/CVERecord?id=CVE-2026-102731
[1] https://security-tracker.debian.org/tracker/CVE-2026-103552
https://www.cve.org/CVERecord?id=CVE-2026-103552
[2] https://security-tracker.debian.org/tracker/CVE-2026-103877
https://www.cve.org/CVERecord?id=CVE-2026-103877
[3] https://security-tracker.debian.org/tracker/CVE-2026-103878
https://www.cve.org/CVERecord?id=CVE-2026-103878
[4] https://security-tracker.debian.org/tracker/CVE-2026-103880
https://www.cve.org/CVERecord?id=CVE-2026-103880
[5] https://security-tracker.debian.org/tracker/CVE-2026-103885
https://www.cve.org/CVERecord?id=CVE-2026-103885

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore