OCTOBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-103552

HIGH · CVSS 7.3 EPSS 0.34%

Source: NVD + CISA KEV + EPSS · Published 2026-10-02 · Last synced 2026-10-07

CyberRota Analysis

AI-Generated

The Apache Directory LDAP API is vulnerable to a stack overflow caused by deeply nested search filters sent by clients before binding, potentially leading to server crashes or denial of service. Organizations using affected versions (1.2.0 to 1.2.8) should prioritize upgrading to version 1.2.9 to mitigate this risk. This vulnerability is particularly relevant for system administrators and security teams managing LDAP services within their infrastructure.

CVE
CVE-2026-103552
Severity
HIGH
CVSS
7.3
EPSS
0.34%
Apache

Original NVD Description

Stack Overflow vulnerability in Apache Directory LDAP API. Before binding, a client can send a deeply nested search filter that overflows the stack in the server's decoder. This issue affects Apache Directory LDAP API: from 1.2.0 before 1.2.9. Users are recommended to upgrade to version 1.2.9, which fixes the issue.