rootpwn

high · CVSS v3 7.3 · EPSS 0.00181

CVE-2026-103552

Apache Directory LDAP API has a stack overflow due to deeply nested search filters before binding, which can crash the server and cause deni

Overview

Apache Directory LDAP API has a stack overflow due to deeply nested search filters before binding, which can crash the server and cause denial of service. The flaw affects versions 1.2.0 through 1.2.8.

Description

Stack Overflow vulnerability in Apache Directory LDAP API. Before binding, a client can send a deeply nested search filter that overflows the stack in the server's decoder. This issue affects Apache Directory LDAP API: from 1.2.0 before 1.2.9. Users are recommended to upgrade to version 1.2.9, which fixes the issue.

Impact

Availability: Denial of Service due to server crash. Confidentiality and Integrity are not directly affected. Impacted parties are LDAP service operators and administrators.

Remediation

Upgrade to Apache Directory LDAP API 1.2.9 or later. If upgrade is not immediately possible, restrict client connections and monitor for abnormal filter depth. Apply firewall rules to limit request size.

Risk context

Severity is high with CVSS 7.3 and EPSS 0.00181, indicating low probability but high impact. Defenders should prioritize patching promptly to mitigate potential DoS.

Affected products

  • Apache Directory LDAP API 1.2.0-1.2.8

Scores

Severity
high
CVSS v2
7.5
CVSS v3
7.3
CVSS v4
—
EPSS
0.00181

stack-overflow ldap denial-of-service apache high-severity patch server-crash

← All CVEs