Description
Asymmetric Resource Consumption vulnerability in Apache Directory LDAP API.



Storing a password using the bcrypt algorithm with a high force like 30 in a LDAP server that supports this algorithm will cause the server CPU to  run for hours checking the credentials. A bounded cost should be enforced to avoid a server DOS.



This issue affects Apache Directory LDAP API: from 2.1.0 before 2.1.9.



Users are recommended to upgrade to version 2.1.9, which fixes the issue.
Published: 2026-10-02
Score: n/a
EPSS: n/a
KEV: No
Impact: Denial of Service
Action: Immediate Patch
AI Analysis

Impact

Storing passwords with an excessively high bcrypt cost factor such as 30 in the Apache Directory LDAP API causes the server to spend extensive CPU cycles validating credentials. This excessive resource consumption can cause the LDAP server to become unresponsive for hours, effectively creating a denial‑of‑service condition. The weakness is a resource exhaustion flaw, classified as CWE‑405, and can compromise availability of the LDAP service.

Affected Systems

The vulnerable software is Apache Directory LDAP API version 2.1.0 through 2.1.8. Users running any of these releases are susceptible; versions 2.1.9 and later include the patch.

Risk and Exploitability

The vulnerability is high impact but the attack requires the ability to write or modify password entries in the LDAP directory, i.e., authentication and write access. The exact exploitation path is inferred from the description: an attacker with such access can set a high bcrypt cost factor and trigger the server’s excessive CPU usage. No EPSS score is available, and the issue is not listed in the CISA KEV catalog, but its potential to cripple directory services warrants a high risk assessment. Immediate patching is advised.

Generated by OpenCVE AI on October 2, 2026 at 11:26 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the official patch by upgrading to Apache Directory LDAP API 2.1.9.
  • Configure the LDAP server to enforce a bounded maximum bcrypt cost factor so that future password entries cannot exceed the safe threshold.
  • Actively monitor CPU usage during authentication and set alerts for unusually high processing times, so any abuse can be detected quickly.

Generated by OpenCVE AI on October 2, 2026 at 11:26 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 02 Oct 2026 14:30:00 +0000

Type Values Removed Values Added
First Time appeared Apache
Apache directory Ldap Api
Vendors & Products Apache
Apache directory Ldap Api

Fri, 02 Oct 2026 10:15:00 +0000

Type Values Removed Values Added
Description Asymmetric Resource Consumption vulnerability in Apache Directory LDAP API. Storing a password using the bcrypt algorithm with a high force like 30 in a LDAP server that supports this algorithm will cause the server CPU to  run for hours checking the credentials. A bounded cost should be enforced to avoid a server DOS. This issue affects Apache Directory LDAP API: from 2.1.0 before 2.1.9. Users are recommended to upgrade to version 2.1.9, which fixes the issue.
Title Apache Directory LDAP API: Denial of service via excessive bcrypt cost factor in stored passwords
Weaknesses CWE-405
References

Subscriptions

Apache Directory Ldap Api
cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published:

Updated: 2026-10-02T10:03:48.296Z

Reserved: 2026-10-01T13:05:10.819Z

Link: CVE-2026-103880

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-10-02T10:17:06.700

Modified: 2026-10-02T14:30:28.440

Link: CVE-2026-103880

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-02T14:15:14Z

Weaknesses
  • CWE-405

    Asymmetric Resource Consumption (Amplification)