Security advisories in the AI and data stack

Severe, 6 weeks2979Projects319

Apache Directory LDAP API: unsafe deserialization

UnratedCVE-2026-103877 · Published Oct 2, 2026

Deserialization of Untrusted Data vulnerability in Apache Directory LDAP API. A rogue/compromised LDAP server (or pre-TLS MITM) can answer a client's loadSchema() subschema search with a schema object that contains a serialized Java class, allowing some potential RCE.  This issue affects Apache Directory LDAP API: from 2.1.0 before 2.1.9. Users are recommended to upgrade to version 2.1.9, which fixes the issue.

Affected versions

PackageAffectedFixed in
Apache Directory LDAP API
Product
>= 2.1.0, < 2.1.92.1.9
Details and references

More Apache Software Foundation advisories

All Apache Software Foundation
Advisory
Apache Thrift: resource exhaustion
High8.2Oct 2
Apache Thrift: resource exhaustion
High8.2Oct 2
Apache Thrift: resource exhaustion
High8.2Oct 2
Apache Thrift: infinite loop
High8.2Oct 2
Apache Thrift: infinite loop
High8.2Oct 2
Apache Thrift: integer overflow
Critical9.2Oct 2