CVE-2026-78243 PUBLISHED

Apache YuniKorn: LDAP Group provider panics on lowercase attribute name

Assigner: apache
Reserved: 24.08.2026 Published: 07.10.2026 Updated: 07.10.2026

Apache YuniKorn 1.8.0 and later, if configured with the LDAP group resolver, crashes due to an out of bounds read processing group membership entries.If the LDAP server returns a group membership entry, memberOf attribute, for a user specified in the pod the server crashes if a membership record does not start with "CN=".

This only affects install that have the non default LDAP group provider configured. 

Users are recommended to upgrade to version 1.10.0, which fixes this issue.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:L/S:N/AU:N/R:A/V:D/RE:H/U:Green
CVSS Score: 2.1

Product Status

Vendor Apache Software Foundation
Product Apache YuniKorn
Versions Default: unaffected
  • affected from 1.8.0 to 1.10.0 (excl.)

Credits

  • gjoko@zeroscience.mk finder

References

Problem Types

  • CWE-248 Uncaught exception CWE