← All Advisories

CVE-2026-103880

Last refreshed2026-10-03

Status: UPDATED  |  Advisory ID: CVE-2026-103880

Key Details

CVECVE-2026-103880
Affected productsApache Software Foundation Apache Directory LDAP API
Classified asCWE-405 (Asymmetric Resource Consumption (Amplification))

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
Apache Software FoundationApache Directory LDAP API
SubsystemsGeneral OT
SectorsMultiple

What to Know

Asymmetric Resource Consumption vulnerability in Apache Directory LDAP API.

Storing a password using the bcrypt algorithm with a high force like 30 in a LDAP server that supports this algorithm will cause the server CPU to  run for hours checking the credentials. A bounded cost should be enforced to avoid a server DOS.

This issue affects Apache Directory LDAP API: from 2.1.0 before 2.1.9.

Users are recommended to upgrade to version 2.1.9, which fixes the issue. (NVD)

What to Do

Monitor Apache Software Foundation's web page for any future patch releases.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-103880
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-103880