Security advisories in the AI and data stack

Severe, 6 weeks2979Projects319

Asymmetric Resource Consumption vulnerability in Apache Directory LDAP API

High7.5CVE-2026-103880 · Published Oct 2, 2026 · updated Oct 5, 2026

Asymmetric Resource Consumption vulnerability in Apache Directory LDAP API. Storing a password using the bcrypt algorithm with a high force like 30 in a LDAP server that supports this algorithm will cause the server CPU to  run for hours checking the credentials. A bounded cost should be enforced to avoid a server DOS. This issue affects Apache Directory LDAP API: from 2.1.0 before 2.1.9. Users are recommended to upgrade to version 2.1.9, which fixes the issue.

Affected versions

PackageAffectedFixed in
Apache Directory LDAP API
Product
>= 2.1.0, < 2.1.92.1.9
Details and references

More Apache Software Foundation advisories

All Apache Software Foundation
Advisory
Apache Thrift: resource exhaustion
High8.2Oct 2
Apache Thrift: resource exhaustion
High8.2Oct 2
Apache Thrift: resource exhaustion
High8.2Oct 2
Apache Thrift: infinite loop
High8.2Oct 2
Apache Thrift: infinite loop
High8.2Oct 2
Apache Thrift: integer overflow
Critical9.2Oct 2