Description
Memory allocation with excessive size value vulnerability in Apache Directory LDAP API.



A malicious peer (or a MITM) can send a small BER-encoded response causing a large memory allocation before any data is received. This can lead to an OutOfMemoryError and denial of service.



The client JVM OOMs (OutOfMemoryError bypasses the DecoderException handlers) or pins the large allocation per connection while the attacker stalls.



A handful of connections exhausts any heap. The same bytes from an unauthenticated pre-bind client hit any embedding server that did not set MAX_PDU_SIZE_ATTR.



This issue affects Apache Directory LDAP API: from 1.2.0 before 1.2.9.



Users are recommended to upgrade to version 1.2.9, which fixes the issue.
Published: 2026-10-02
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Immediate Patch
AI Analysis

Impact

A small BER-encoded response can trigger the LDAP API to allocate a memory block with an overly large size value. The resulting OutOfMemoryError bypasses normal decoder exceptions and can cause the entire client JVM to crash or the server to stall. Because the allocation happens before any data is processed, the attack can be carried out remotely by a connection peer or a MITM attacker. The primary consequence is a denial of service that can exhaust the heap and keep the service unavailable until a restart or manual intervention. This weakness corresponds to the "Excessive Allocation" category associated with CWE-770 and CWE-789.

Affected Systems

The vulnerability affects the Apache Directory LDAP API distributed by the Apache Software Foundation. Versions 1.2.0 through the last entry before 1.2.9 are susceptible. Any client or embedding server that uses a pre‑bind client without setting a maximum PDU size attribute can be impacted.

Risk and Exploitability

The CVSS score is 7.5, indicating a high severity vulnerability, and the EPSS score is less than 1%, suggesting a low but nonzero probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. Attackers need no authentication and can target any open LDAP connection, making the potential impact significant. Because a handful of poorly throttled connections can exhaust the heap, large-scale denial of service is achievable with minimal effort. While no public exploit has been documented, the vulnerability remains a low-hanging fruit for adversaries once a suitable client exists.

Generated by OpenCVE AI on October 3, 2026 at 01:27 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to Apache Directory LDAP API version 1.2.9 or newer, which removes the excessive allocation bug.
  • If upgrading is not immediately possible, enforce strict limits on the size of inbound BER messages and enforce connection throttling in the surrounding infrastructure.
  • Monitor JVM memory usage for signs of OutOfMemoryError and plan for service restarts or resource allocation adjustments accordingly.

Generated by OpenCVE AI on October 3, 2026 at 01:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 03 Oct 2026 00:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-770
References
Metrics threat_severity

None

cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}

threat_severity

Important


Fri, 02 Oct 2026 22:30:00 +0000

Type Values Removed Values Added
References

Fri, 02 Oct 2026 10:45:00 +0000

Type Values Removed Values Added
First Time appeared Apache
Apache directory Ldap Api
Vendors & Products Apache
Apache directory Ldap Api

Fri, 02 Oct 2026 09:30:00 +0000

Type Values Removed Values Added
Description Memory allocation with excessive size value vulnerability in Apache Directory LDAP API. A malicious peer (or a MITM) can send a small BER-encoded response causing a large memory allocation before any data is received. This can lead to an OutOfMemoryError and denial of service. The client JVM OOMs (OutOfMemoryError bypasses the DecoderException handlers) or pins the large allocation per connection while the attacker stalls. A handful of connections exhausts any heap. The same bytes from an unauthenticated pre-bind client hit any embedding server that did not set MAX_PDU_SIZE_ATTR. This issue affects Apache Directory LDAP API: from 1.2.0 before 1.2.9. Users are recommended to upgrade to version 1.2.9, which fixes the issue.
Title Apache Directory LDAP API: Denial of service via excessive memory allocation in BER decode
Weaknesses CWE-789
References

Subscriptions

Apache Directory Ldap Api
cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published:

Updated: 2026-10-02T21:07:18.741Z

Reserved: 2026-09-29T16:17:56.332Z

Link: CVE-2026-102731

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-10-02T10:17:04.530

Modified: 2026-10-02T22:16:53.290

Link: CVE-2026-102731

cve-icon Redhat

Severity : Important

Publid Date: 2026-10-02T09:22:00Z

Links: CVE-2026-102731 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-10-03T01:30:18Z

Weaknesses
  • CWE-770

    Allocation of Resources Without Limits or Throttling

  • CWE-789

    Memory Allocation with Excessive Size Value