CVE-2026-103552 PUBLISHED

Apache Directory LDAP API: A unbound client can send a deeply nested search filter that overflows the stack in the server's decoder

Assigner: apache
Reserved: 30.09.2026 Published: 02.10.2026 Updated: 02.10.2026

Stack Overflow vulnerability in Apache Directory LDAP API.

Before binding, a client can send a deeply nested search filter that overflows the stack in the server's decoder.

This issue affects Apache Directory LDAP API: from 1.2.0 before 1.2.9.

Users are recommended to upgrade to version 1.2.9, which fixes the issue.

Product Status

Vendor Apache Software Foundation
Product Apache Directory LDAP API
Versions Default: unaffected
  • affected from 1.2.0 to 1.2.9 (excl.)

Credits

  • Claude Security tool
  • The Apache Software Foundation finder

References

Problem Types

  • CWE-121 Stack-based buffer overflow CWE