Security advisories in the AI and data stack

Severe, 6 weeks2979Projects319

Apache Directory LDAP API: cleartext secrets

High7.5CVE-2026-103878 · Published Oct 2, 2026 · updated Oct 5, 2026

Cleartext transmission of sensitive information vulnerability in Apache Directory LDAP API. A StartTLS extended operation started after a Search request has been sent can lead to receive data in plain text before the TLS Handshake has been completed. This issue affects Apache Directory LDAP API: from 2.1.0 before 2.1.9. Users are recommended to upgrade to version 2.1.9, which fixes the issue.

Affected versions

PackageAffectedFixed in
Apache Directory LDAP API
Product
>= 2.1.0, < 2.1.92.1.9
Details and references

More Apache Software Foundation advisories

All Apache Software Foundation
Advisory
Apache Thrift: resource exhaustion
High8.2Oct 2
Apache Thrift: resource exhaustion
High8.2Oct 2
Apache Thrift: resource exhaustion
High8.2Oct 2
Apache Thrift: infinite loop
High8.2Oct 2
Apache Thrift: infinite loop
High8.2Oct 2
Apache Thrift: integer overflow
Critical9.2Oct 2