OCTOBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-103880

HIGH · CVSS 7.5 EPSS 0.49%

Source: NVD + CISA KEV + EPSS · Published 2026-10-02 · Last synced 2026-10-07

CyberRota Analysis

AI-Generated

The Apache Directory LDAP API is vulnerable to an asymmetric resource consumption issue that can lead to prolonged CPU usage when verifying bcrypt passwords with a high cost factor, potentially resulting in a denial-of-service condition. Organizations using affected versions (2.1.0 to 2.1.8) should prioritize upgrading to version 2.1.9 to mitigate this risk and ensure server stability.

CVE
CVE-2026-103880
Severity
HIGH
CVSS
7.5
EPSS
0.49%
Apache

Original NVD Description

Asymmetric Resource Consumption vulnerability in Apache Directory LDAP API. Storing a password using the bcrypt algorithm with a high force like 30 in a LDAP server that supports this algorithm will cause the server CPU to  run for hours checking the credentials. A bounded cost should be enforced to avoid a server DOS. This issue affects Apache Directory LDAP API: from 2.1.0 before 2.1.9. Users are recommended to upgrade to version 2.1.9, which fixes the issue.