org.apache.directory.api/api-asn1-ber: Apache Directory LDAP API: Denial of Service via excessive memory allocation

cve CVE-2026-102731 3 sources, 3 claims · Watch

Red Hat writes:
org.apache.directory.api/api-asn1-ber: Apache Directory LDAP API: Denial of Service via excessive memory allocation the claim

What it is to other things

In words only, so not counted until a person confirms one:

affectsapache_software_foundation/apache_directory_ldap_api
NVD says “Apache Software Foundation · Apache Directory LDAP API”
made_byapache_software_foundation
NVD says “Apache Software Foundation”

What each source says

PropertySourceSaidMeans here
Cvss
cvss
Red Hat7.5
receipt
Source
Red Hat
Its words
7.5
Read by
field:cvss3_score
Said since
2026-10-03 00:06 UTC
Last answered
2026-10-05 12:24 UTC
Original
open at the source
What the source handed over
{
  "CVE": "CVE-2026-102731",
  "CWE": "CWE-770",
  "advisories": [],
  "affected_packages": [],
  "bugzilla": "2544985",
  "bugzilla_description": "org.apache.directory.api/api-asn1-ber: Apache Directory LDAP API: Denial of Service via excessive memory allocation",
  "cvss3_score": "7.5",
  "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
  "cvss_score": null,
  "cvss_scoring_vector": null,
  "package_state": null,
  "public_date": "2026-10-02T09:22:00Z",
  "resource_url": "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2026-102731.json",
  "severity": "important"
}
—
Cwe
cwe
not compared
GitHub advisoriesCWE-789
receipt
Source
GitHub advisories
Its words
CWE-789
Read by
field:cwes[].cwe_id
Said since
2026-10-02 18:00 UTC
Last answered
2026-10-05 12:22 UTC
Original
open at the source
What the source handed over
{
  "comments": 0,
  "credits": [],
  "cve_id": "CVE-2026-102731",
  "cvss": {
    "score": null,
    "vector_string": null
  },
  "cvss_severities": {
    "cvss_v3": {
      "score": 0.0,
      "vector_string": null
    },
    "cvss_v4": {
      "score": 0.0,
      "vector_string": null
    }
  },
  "cwes": [
    {
      "cwe_id": "CWE-789",
      "name": "Memory Allocation with Excessive Size Value"
    }
  ],
  "description": "Memory allocation with excessive size value vulnerability in Apache Directory LDAP API.\n\n\n\nA malicious peer (or a MITM) can send a small BER-encoded response causing a large memory allocation before any data is received. This can lead to an OutOfMemoryError and denial of service.\n\n\n\nThe client JVM OOMs (OutOfMemoryError bypasses the DecoderException handlers) or pins the large allocation per connection while the attacker stalls.\n\n\n\nA handful of connections exhausts any heap. The same bytes from an unauthenticated pre-bind client hit any embedding server that did not set MAX_PDU_SIZE_ATTR.\n\n\n\nThis issue affects Apache Directory LDAP API: from 1.2.0 before 1.2.9.\n\n\n\nUsers are recommended to upgrade to version 1.2.9, which fixes the issue.",
  "ghsa_id": "GHSA-h24g-pjpf-8f2m",
  "github_reviewed_at": null,
  "html_url": "https://github.com/advisories/GHSA-h24g-pjpf-8f2m",
  "identifiers": [
    {
      "type": "GHSA",
      "value": "GHSA-h24g-pjpf-8f2m"
    },
    {
      "type": "CVE",
      "value": "CVE-2026-102731"
    }
  ],
  "nvd_published_at": "2026-10-02T10:17:04Z",
  "published_at": "2026-10-02T12:31:09Z",
  "references": [
    "https://nvd.nist.gov/vuln/detail/CVE-2026-102731",
    "https://lists.apache.org/thread.html/b8kg8881pc0v8lp59w0fcfrs69wjbqvd",
    "https://github.com/advisories/GHSA-h24g-pjpf-8f2m"
  ],
  "repository_advisory_url": null,
  "severity": "unknown",
  "source_code_location": "",
  "summary": "Memory allocation with excessive size value vulnerability in Apache Directory LDAP API.\n\n\n\nA...",
  "type": "unreviewed",
  "updated_at": "2026-10-02T12:31:18Z",
  "url": "https://api.github.com/advisories/GHSA-h24g-pjpf-8f2m",
  "vulnerabilities": [],
  "withdrawn_at": null
}
—
Cwe
cwe
not compared
Red HatCWE-770
receipt
Source
Red Hat
Its words
CWE-770
Read by
field:CWE
Said since
2026-10-03 00:06 UTC
Last answered
2026-10-05 12:24 UTC
Original
open at the source
What the source handed over
{
  "CVE": "CVE-2026-102731",
  "CWE": "CWE-770",
  "advisories": [],
  "affected_packages": [],
  "bugzilla": "2544985",
  "bugzilla_description": "org.apache.directory.api/api-asn1-ber: Apache Directory LDAP API: Denial of Service via excessive memory allocation",
  "cvss3_score": "7.5",
  "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
  "cvss_score": null,
  "cvss_scoring_vector": null,
  "package_state": null,
  "public_date": "2026-10-02T09:22:00Z",
  "resource_url": "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2026-102731.json",
  "severity": "important"
}
—
Product
product
NVDApache Directory LDAP API
receipt
Source
NVD
Its words
Apache Directory LDAP API
Read by
field:cve.affected[].affectedData[].product
Said since
2026-10-02 12:00 UTC
Last answered
2026-10-05 12:24 UTC
Original
open at the source
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "collectionURL": "https://repo.maven.apache.org/maven2",
            "defaultStatus": "unaffected",
            "packageName": "org.apache.directory.api:api-asn1-ber",
            "packageURL": "pkg:maven/org.apache.directory.api/api-asn1-ber",
            "product": "Apache Directory LDAP API",
            "vendor": "Apache Software Foundation",
            "versions": [
              {
                "lessThan": "1.2.9",
                "status": "affected",
                "version": "1.2.0",
                "versionType": "semver"
              }
            ]
          }
        ],
        "source": "security@apache.org"
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "Memory allocation with excessive size value vulnerability in Apache Directory LDAP API.\n\n\n\nA malicious peer (or a MITM) can send a small BER-encoded response causing a large memory allocation before any data is received. This can lead to an OutOfMemoryError and denial of service.\n\n\n\nThe client JVM OOMs (OutOfMemoryError bypasses the DecoderException handlers) or pins the large allocation per connection while the attacker stalls.\n\n\n\nA handful of connections exhausts any heap. The same bytes from an unauthenticated pre-bind client hit any embedding server that did not set MAX_PDU_SIZE_ATTR.\n\n\n\nThis issue affects Apache Directory LDAP API: from 1.2.0 before 1.2.9.\n\n\n\nUsers are recommended to upgrade to version 1.2.9, which fixes the issue."
      }
    ],
    "id": "CVE-2026-102731",
    "lastModified": "2026-10-02T14:30:28.440",
    "metrics": {},
    "published": "2026-10-02T10:17:04.530",
    "references": [
      {
        "source": "security@apache.org",
        "url": "https://lists.apache.org/thread.html/b8kg8881pc0v8lp59w0fcfrs69wjbqvd"
      }
    ],
    "sourceIdentifier": "security@apache.org",
    "vulnStatus": "Deferred",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-789"
          }
        ],
        "source": "security@apache.org",
        "type": "Primary"
      }
    ]
  }
}
—
Severity
severity
conflict
GitHub advisoriesunknown
receipt
Source
GitHub advisories
Its words
unknown
Read by
field:severity
Said since
2026-10-02 18:00 UTC
Last answered
2026-10-05 12:22 UTC
Original
open at the source
What the source handed over
{
  "comments": 0,
  "credits": [],
  "cve_id": "CVE-2026-102731",
  "cvss": {
    "score": null,
    "vector_string": null
  },
  "cvss_severities": {
    "cvss_v3": {
      "score": 0.0,
      "vector_string": null
    },
    "cvss_v4": {
      "score": 0.0,
      "vector_string": null
    }
  },
  "cwes": [
    {
      "cwe_id": "CWE-789",
      "name": "Memory Allocation with Excessive Size Value"
    }
  ],
  "description": "Memory allocation with excessive size value vulnerability in Apache Directory LDAP API.\n\n\n\nA malicious peer (or a MITM) can send a small BER-encoded response causing a large memory allocation before any data is received. This can lead to an OutOfMemoryError and denial of service.\n\n\n\nThe client JVM OOMs (OutOfMemoryError bypasses the DecoderException handlers) or pins the large allocation per connection while the attacker stalls.\n\n\n\nA handful of connections exhausts any heap. The same bytes from an unauthenticated pre-bind client hit any embedding server that did not set MAX_PDU_SIZE_ATTR.\n\n\n\nThis issue affects Apache Directory LDAP API: from 1.2.0 before 1.2.9.\n\n\n\nUsers are recommended to upgrade to version 1.2.9, which fixes the issue.",
  "ghsa_id": "GHSA-h24g-pjpf-8f2m",
  "github_reviewed_at": null,
  "html_url": "https://github.com/advisories/GHSA-h24g-pjpf-8f2m",
  "identifiers": [
    {
      "type": "GHSA",
      "value": "GHSA-h24g-pjpf-8f2m"
    },
    {
      "type": "CVE",
      "value": "CVE-2026-102731"
    }
  ],
  "nvd_published_at": "2026-10-02T10:17:04Z",
  "published_at": "2026-10-02T12:31:09Z",
  "references": [
    "https://nvd.nist.gov/vuln/detail/CVE-2026-102731",
    "https://lists.apache.org/thread.html/b8kg8881pc0v8lp59w0fcfrs69wjbqvd",
    "https://github.com/advisories/GHSA-h24g-pjpf-8f2m"
  ],
  "repository_advisory_url": null,
  "severity": "unknown",
  "source_code_location": "",
  "summary": "Memory allocation with excessive size value vulnerability in Apache Directory LDAP API.\n\n\n\nA...",
  "type": "unreviewed",
  "updated_at": "2026-10-02T12:31:18Z",
  "url": "https://api.github.com/advisories/GHSA-h24g-pjpf-8f2m",
  "vulnerabilities": [],
  "withdrawn_at": null
}
—
Severity
severity
conflict
Red Hatimportant
A flaw that can easily compromise confidentiality, integrity or availability.
receipt
Source
Red Hat
Its words
important
Read by
field:severity
Said since
2026-10-03 00:06 UTC
Last answered
2026-10-05 12:24 UTC
Original
open at the source
What the source handed over
{
  "CVE": "CVE-2026-102731",
  "CWE": "CWE-770",
  "advisories": [],
  "affected_packages": [],
  "bugzilla": "2544985",
  "bugzilla_description": "org.apache.directory.api/api-asn1-ber: Apache Directory LDAP API: Denial of Service via excessive memory allocation",
  "cvss3_score": "7.5",
  "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
  "cvss_score": null,
  "cvss_scoring_vector": null,
  "package_state": null,
  "public_date": "2026-10-02T09:22:00Z",
  "resource_url": "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2026-102731.json",
  "severity": "important"
}
high
Status
status
NVDDeferred
receipt
Source
NVD
Its words
Deferred
Read by
field:cve.vulnStatus
Said since
2026-10-02 18:03 UTC
Last answered
2026-10-05 12:24 UTC
Original
open at the source
2026-10-02 18:03 UTCDeferred
2026-10-02 12:00 UTCReceived
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "collectionURL": "https://repo.maven.apache.org/maven2",
            "defaultStatus": "unaffected",
            "packageName": "org.apache.directory.api:api-asn1-ber",
            "packageURL": "pkg:maven/org.apache.directory.api/api-asn1-ber",
            "product": "Apache Directory LDAP API",
            "vendor": "Apache Software Foundation",
            "versions": [
              {
                "lessThan": "1.2.9",
                "status": "affected",
                "version": "1.2.0",
                "versionType": "semver"
              }
            ]
          }
        ],
        "source": "security@apache.org"
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "Memory allocation with excessive size value vulnerability in Apache Directory LDAP API.\n\n\n\nA malicious peer (or a MITM) can send a small BER-encoded response causing a large memory allocation before any data is received. This can lead to an OutOfMemoryError and denial of service.\n\n\n\nThe client JVM OOMs (OutOfMemoryError bypasses the DecoderException handlers) or pins the large allocation per connection while the attacker stalls.\n\n\n\nA handful of connections exhausts any heap. The same bytes from an unauthenticated pre-bind client hit any embedding server that did not set MAX_PDU_SIZE_ATTR.\n\n\n\nThis issue affects Apache Directory LDAP API: from 1.2.0 before 1.2.9.\n\n\n\nUsers are recommended to upgrade to version 1.2.9, which fixes the issue."
      }
    ],
    "id": "CVE-2026-102731",
    "lastModified": "2026-10-02T14:30:28.440",
    "metrics": {},
    "published": "2026-10-02T10:17:04.530",
    "references": [
      {
        "source": "security@apache.org",
        "url": "https://lists.apache.org/thread.html/b8kg8881pc0v8lp59w0fcfrs69wjbqvd"
      }
    ],
    "sourceIdentifier": "security@apache.org",
    "vulnStatus": "Deferred",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-789"
          }
        ],
        "source": "security@apache.org",
        "type": "Primary"
      }
    ]
  }
}
—
Vendor
vendor
NVDApache Software Foundation
receipt
Source
NVD
Its words
Apache Software Foundation
Read by
field:cve.affected[].affectedData[].vendor
Said since
2026-10-02 12:00 UTC
Last answered
2026-10-05 12:24 UTC
Original
open at the source
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "collectionURL": "https://repo.maven.apache.org/maven2",
            "defaultStatus": "unaffected",
            "packageName": "org.apache.directory.api:api-asn1-ber",
            "packageURL": "pkg:maven/org.apache.directory.api/api-asn1-ber",
            "product": "Apache Directory LDAP API",
            "vendor": "Apache Software Foundation",
            "versions": [
              {
                "lessThan": "1.2.9",
                "status": "affected",
                "version": "1.2.0",
                "versionType": "semver"
              }
            ]
          }
        ],
        "source": "security@apache.org"
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "Memory allocation with excessive size value vulnerability in Apache Directory LDAP API.\n\n\n\nA malicious peer (or a MITM) can send a small BER-encoded response causing a large memory allocation before any data is received. This can lead to an OutOfMemoryError and denial of service.\n\n\n\nThe client JVM OOMs (OutOfMemoryError bypasses the DecoderException handlers) or pins the large allocation per connection while the attacker stalls.\n\n\n\nA handful of connections exhausts any heap. The same bytes from an unauthenticated pre-bind client hit any embedding server that did not set MAX_PDU_SIZE_ATTR.\n\n\n\nThis issue affects Apache Directory LDAP API: from 1.2.0 before 1.2.9.\n\n\n\nUsers are recommended to upgrade to version 1.2.9, which fixes the issue."
      }
    ],
    "id": "CVE-2026-102731",
    "lastModified": "2026-10-02T14:30:28.440",
    "metrics": {},
    "published": "2026-10-02T10:17:04.530",
    "references": [
      {
        "source": "security@apache.org",
        "url": "https://lists.apache.org/thread.html/b8kg8881pc0v8lp59w0fcfrs69wjbqvd"
      }
    ],
    "sourceIdentifier": "security@apache.org",
    "vulnStatus": "Deferred",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-789"
          }
        ],
        "source": "security@apache.org",
        "type": "Primary"
      }
    ]
  }
}
—

vulnerability

org.apache.directory.api/api-asn1-ber: Apache Directory LDAP API: Denial of Service via excessive memory allocation
zetlyn/cve-redhat · 2026-10-02
cvss 7.5 cwe CWE-770 severity important source
Memory allocation with excessive size value vulnerability in Apache Directory LDAP API. A malicious peer (or a MITM) can send a small BER-encoded response causing a large memory allocation before any data is received. This can lead to an OutOfMemoryError and denial of service. The client JVM OOMs (OutOfMemoryError bypasses the DecoderException handlers) or pins the large allocation per connection while the attacker stalls. A handful of connections exhausts any heap. The same bytes from an unauthenticated pre-bind client hit any embedding server that did not set MAX_PDU_SIZE_ATTR. This issue affects Apache Directory LDAP API: from 1.2.0 before 1.2.9. Users are recommended to upgrade to version 1.2.9, which fixes the issue.
zetlyn/cve-nvd · 2026-10-02
product Apache Directory LDAP API status Deferred vendor Apache Software Foundation source
Memory allocation with excessive size value vulnerability in Apache Directory LDAP API. A...
zetlyn/cve-ghsa · 2026-10-02
cwe CWE-789 severity unknown source