OCTOBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-102731

HIGH · CVSS 7.5 EPSS 0.43%

Source: NVD + CISA KEV + EPSS · Published 2026-10-02 · Last synced 2026-10-07

CyberRota Analysis

AI-Generated

The Apache Directory LDAP API is vulnerable to a memory allocation issue that can be exploited by a malicious peer or a man-in-the-middle attacker, leading to an OutOfMemoryError and subsequent denial of service. This vulnerability allows an attacker to send a small BER-encoded response that triggers excessive memory allocation, potentially exhausting the heap with just a few connections. Organizations using affected versions (1.2.0 to 1.2.8) should prioritize upgrading to version 1.2.9 to mitigate this risk.

CVE
CVE-2026-102731
Severity
HIGH
CVSS
7.5
EPSS
0.43%
Apache

Original NVD Description

Memory allocation with excessive size value vulnerability in Apache Directory LDAP API. A malicious peer (or a MITM) can send a small BER-encoded response causing a large memory allocation before any data is received. This can lead to an OutOfMemoryError and denial of service. The client JVM OOMs (OutOfMemoryError bypasses the DecoderException handlers) or pins the large allocation per connection while the attacker stalls. A handful of connections exhausts any heap. The same bytes from an unauthenticated pre-bind client hit any embedding server that did not set MAX_PDU_SIZE_ATTR. This issue affects Apache Directory LDAP API: from 1.2.0 before 1.2.9. Users are recommended to upgrade to version 1.2.9, which fixes the issue.