← All Advisories

CVE-2026-103885

Last refreshed2026-10-03

Status: UPDATED  |  Advisory ID: CVE-2026-103885

Key Details

CVECVE-2026-103885
Affected productsApache Software Foundation Apache Directory LDAP API

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
Apache Software FoundationApache Directory LDAP API
SubsystemsGeneral OT
SectorsMultiple

What to Know

Asymmetric Resource Consumption vulnerability in Apache Directory LDAP API.

A LDAP server using the LDAP API (like Apache DS) may consume 100% of a CPU core indefinitely when processing some badly crafted Telephone Numbers.

This issue affects Apache Directory LDAP API: from 2.1.0 before 2.1.9.

Users are recommended to upgrade to version 2.1.9, which fixes the issue. (NVD)

What to Do

Monitor Apache Software Foundation's web page for any future patch releases.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-103885
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-103885