org.apache.directory.api/api-asn1-ber: Apache Directory LDAP API: Denial of Service via excessive memory allocation
cve CVE-2026-102731 3 sources, 3 claims · Watch
Red Hat writes:
org.apache.directory.api/api-asn1-ber: Apache Directory LDAP API: Denial of Service via excessive memory allocation the claim
org.apache.directory.api/api-asn1-ber: Apache Directory LDAP API: Denial of Service via excessive memory allocation the claim
What it is to other things
In words only, so not counted until a person confirms one:
| affects | apache_software_foundation/apache_directory_ldap_apiNVD says “Apache Software Foundation · Apache Directory LDAP API” |
| made_by | apache_software_foundationNVD says “Apache Software Foundation” |
What each source says
| Property | Source | Said | Means here | ||||
|---|---|---|---|---|---|---|---|
| Cvss cvss | Red Hat | 7.5receipt
What the source handed over{
"CVE": "CVE-2026-102731",
"CWE": "CWE-770",
"advisories": [],
"affected_packages": [],
"bugzilla": "2544985",
"bugzilla_description": "org.apache.directory.api/api-asn1-ber: Apache Directory LDAP API: Denial of Service via excessive memory allocation",
"cvss3_score": "7.5",
"cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"cvss_score": null,
"cvss_scoring_vector": null,
"package_state": null,
"public_date": "2026-10-02T09:22:00Z",
"resource_url": "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2026-102731.json",
"severity": "important"
} | — | ||||
| Cwe cwe not compared | GitHub advisories | CWE-789receipt
What the source handed over{
"comments": 0,
"credits": [],
"cve_id": "CVE-2026-102731",
"cvss": {
"score": null,
"vector_string": null
},
"cvss_severities": {
"cvss_v3": {
"score": 0.0,
"vector_string": null
},
"cvss_v4": {
"score": 0.0,
"vector_string": null
}
},
"cwes": [
{
"cwe_id": "CWE-789",
"name": "Memory Allocation with Excessive Size Value"
}
],
"description": "Memory allocation with excessive size value vulnerability in Apache Directory LDAP API.\n\n\n\nA malicious peer (or a MITM) can send a small BER-encoded response causing a large memory allocation before any data is received. This can lead to an OutOfMemoryError and denial of service.\n\n\n\nThe client JVM OOMs (OutOfMemoryError bypasses the DecoderException handlers) or pins the large allocation per connection while the attacker stalls.\n\n\n\nA handful of connections exhausts any heap. The same bytes from an unauthenticated pre-bind client hit any embedding server that did not set MAX_PDU_SIZE_ATTR.\n\n\n\nThis issue affects Apache Directory LDAP API: from 1.2.0 before 1.2.9.\n\n\n\nUsers are recommended to upgrade to version 1.2.9, which fixes the issue.",
"ghsa_id": "GHSA-h24g-pjpf-8f2m",
"github_reviewed_at": null,
"html_url": "https://github.com/advisories/GHSA-h24g-pjpf-8f2m",
"identifiers": [
{
"type": "GHSA",
"value": "GHSA-h24g-pjpf-8f2m"
},
{
"type": "CVE",
"value": "CVE-2026-102731"
}
],
"nvd_published_at": "2026-10-02T10:17:04Z",
"published_at": "2026-10-02T12:31:09Z",
"references": [
"https://nvd.nist.gov/vuln/detail/CVE-2026-102731",
"https://lists.apache.org/thread.html/b8kg8881pc0v8lp59w0fcfrs69wjbqvd",
"https://github.com/advisories/GHSA-h24g-pjpf-8f2m"
],
"repository_advisory_url": null,
"severity": "unknown",
"source_code_location": "",
"summary": "Memory allocation with excessive size value vulnerability in Apache Directory LDAP API.\n\n\n\nA...",
"type": "unreviewed",
"updated_at": "2026-10-02T12:31:18Z",
"url": "https://api.github.com/advisories/GHSA-h24g-pjpf-8f2m",
"vulnerabilities": [],
"withdrawn_at": null
} | — | ||||
| Cwe cwe not compared | Red Hat | CWE-770receipt
What the source handed over{
"CVE": "CVE-2026-102731",
"CWE": "CWE-770",
"advisories": [],
"affected_packages": [],
"bugzilla": "2544985",
"bugzilla_description": "org.apache.directory.api/api-asn1-ber: Apache Directory LDAP API: Denial of Service via excessive memory allocation",
"cvss3_score": "7.5",
"cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"cvss_score": null,
"cvss_scoring_vector": null,
"package_state": null,
"public_date": "2026-10-02T09:22:00Z",
"resource_url": "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2026-102731.json",
"severity": "important"
} | — | ||||
| Product product | NVD | Apache Directory LDAP APIreceipt
What the source handed over{
"cve": {
"affected": [
{
"affectedData": [
{
"collectionURL": "https://repo.maven.apache.org/maven2",
"defaultStatus": "unaffected",
"packageName": "org.apache.directory.api:api-asn1-ber",
"packageURL": "pkg:maven/org.apache.directory.api/api-asn1-ber",
"product": "Apache Directory LDAP API",
"vendor": "Apache Software Foundation",
"versions": [
{
"lessThan": "1.2.9",
"status": "affected",
"version": "1.2.0",
"versionType": "semver"
}
]
}
],
"source": "security@apache.org"
}
],
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "Memory allocation with excessive size value vulnerability in Apache Directory LDAP API.\n\n\n\nA malicious peer (or a MITM) can send a small BER-encoded response causing a large memory allocation before any data is received. This can lead to an OutOfMemoryError and denial of service.\n\n\n\nThe client JVM OOMs (OutOfMemoryError bypasses the DecoderException handlers) or pins the large allocation per connection while the attacker stalls.\n\n\n\nA handful of connections exhausts any heap. The same bytes from an unauthenticated pre-bind client hit any embedding server that did not set MAX_PDU_SIZE_ATTR.\n\n\n\nThis issue affects Apache Directory LDAP API: from 1.2.0 before 1.2.9.\n\n\n\nUsers are recommended to upgrade to version 1.2.9, which fixes the issue."
}
],
"id": "CVE-2026-102731",
"lastModified": "2026-10-02T14:30:28.440",
"metrics": {},
"published": "2026-10-02T10:17:04.530",
"references": [
{
"source": "security@apache.org",
"url": "https://lists.apache.org/thread.html/b8kg8881pc0v8lp59w0fcfrs69wjbqvd"
}
],
"sourceIdentifier": "security@apache.org",
"vulnStatus": "Deferred",
"weaknesses": [
{
"description": [
{
"lang": "en",
"value": "CWE-789"
}
],
"source": "security@apache.org",
"type": "Primary"
}
]
}
} | — | ||||
| Severity severity conflict | GitHub advisories | unknownreceipt
What the source handed over{
"comments": 0,
"credits": [],
"cve_id": "CVE-2026-102731",
"cvss": {
"score": null,
"vector_string": null
},
"cvss_severities": {
"cvss_v3": {
"score": 0.0,
"vector_string": null
},
"cvss_v4": {
"score": 0.0,
"vector_string": null
}
},
"cwes": [
{
"cwe_id": "CWE-789",
"name": "Memory Allocation with Excessive Size Value"
}
],
"description": "Memory allocation with excessive size value vulnerability in Apache Directory LDAP API.\n\n\n\nA malicious peer (or a MITM) can send a small BER-encoded response causing a large memory allocation before any data is received. This can lead to an OutOfMemoryError and denial of service.\n\n\n\nThe client JVM OOMs (OutOfMemoryError bypasses the DecoderException handlers) or pins the large allocation per connection while the attacker stalls.\n\n\n\nA handful of connections exhausts any heap. The same bytes from an unauthenticated pre-bind client hit any embedding server that did not set MAX_PDU_SIZE_ATTR.\n\n\n\nThis issue affects Apache Directory LDAP API: from 1.2.0 before 1.2.9.\n\n\n\nUsers are recommended to upgrade to version 1.2.9, which fixes the issue.",
"ghsa_id": "GHSA-h24g-pjpf-8f2m",
"github_reviewed_at": null,
"html_url": "https://github.com/advisories/GHSA-h24g-pjpf-8f2m",
"identifiers": [
{
"type": "GHSA",
"value": "GHSA-h24g-pjpf-8f2m"
},
{
"type": "CVE",
"value": "CVE-2026-102731"
}
],
"nvd_published_at": "2026-10-02T10:17:04Z",
"published_at": "2026-10-02T12:31:09Z",
"references": [
"https://nvd.nist.gov/vuln/detail/CVE-2026-102731",
"https://lists.apache.org/thread.html/b8kg8881pc0v8lp59w0fcfrs69wjbqvd",
"https://github.com/advisories/GHSA-h24g-pjpf-8f2m"
],
"repository_advisory_url": null,
"severity": "unknown",
"source_code_location": "",
"summary": "Memory allocation with excessive size value vulnerability in Apache Directory LDAP API.\n\n\n\nA...",
"type": "unreviewed",
"updated_at": "2026-10-02T12:31:18Z",
"url": "https://api.github.com/advisories/GHSA-h24g-pjpf-8f2m",
"vulnerabilities": [],
"withdrawn_at": null
} | — | ||||
| Severity severity conflict | Red Hat | important A flaw that can easily compromise confidentiality, integrity or availability. receipt
What the source handed over{
"CVE": "CVE-2026-102731",
"CWE": "CWE-770",
"advisories": [],
"affected_packages": [],
"bugzilla": "2544985",
"bugzilla_description": "org.apache.directory.api/api-asn1-ber: Apache Directory LDAP API: Denial of Service via excessive memory allocation",
"cvss3_score": "7.5",
"cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"cvss_score": null,
"cvss_scoring_vector": null,
"package_state": null,
"public_date": "2026-10-02T09:22:00Z",
"resource_url": "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2026-102731.json",
"severity": "important"
} | high | ||||
| Status status | NVD | Deferredreceipt
What the source handed over{
"cve": {
"affected": [
{
"affectedData": [
{
"collectionURL": "https://repo.maven.apache.org/maven2",
"defaultStatus": "unaffected",
"packageName": "org.apache.directory.api:api-asn1-ber",
"packageURL": "pkg:maven/org.apache.directory.api/api-asn1-ber",
"product": "Apache Directory LDAP API",
"vendor": "Apache Software Foundation",
"versions": [
{
"lessThan": "1.2.9",
"status": "affected",
"version": "1.2.0",
"versionType": "semver"
}
]
}
],
"source": "security@apache.org"
}
],
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "Memory allocation with excessive size value vulnerability in Apache Directory LDAP API.\n\n\n\nA malicious peer (or a MITM) can send a small BER-encoded response causing a large memory allocation before any data is received. This can lead to an OutOfMemoryError and denial of service.\n\n\n\nThe client JVM OOMs (OutOfMemoryError bypasses the DecoderException handlers) or pins the large allocation per connection while the attacker stalls.\n\n\n\nA handful of connections exhausts any heap. The same bytes from an unauthenticated pre-bind client hit any embedding server that did not set MAX_PDU_SIZE_ATTR.\n\n\n\nThis issue affects Apache Directory LDAP API: from 1.2.0 before 1.2.9.\n\n\n\nUsers are recommended to upgrade to version 1.2.9, which fixes the issue."
}
],
"id": "CVE-2026-102731",
"lastModified": "2026-10-02T14:30:28.440",
"metrics": {},
"published": "2026-10-02T10:17:04.530",
"references": [
{
"source": "security@apache.org",
"url": "https://lists.apache.org/thread.html/b8kg8881pc0v8lp59w0fcfrs69wjbqvd"
}
],
"sourceIdentifier": "security@apache.org",
"vulnStatus": "Deferred",
"weaknesses": [
{
"description": [
{
"lang": "en",
"value": "CWE-789"
}
],
"source": "security@apache.org",
"type": "Primary"
}
]
}
} | — | ||||
| Vendor vendor | NVD | Apache Software Foundationreceipt
What the source handed over{
"cve": {
"affected": [
{
"affectedData": [
{
"collectionURL": "https://repo.maven.apache.org/maven2",
"defaultStatus": "unaffected",
"packageName": "org.apache.directory.api:api-asn1-ber",
"packageURL": "pkg:maven/org.apache.directory.api/api-asn1-ber",
"product": "Apache Directory LDAP API",
"vendor": "Apache Software Foundation",
"versions": [
{
"lessThan": "1.2.9",
"status": "affected",
"version": "1.2.0",
"versionType": "semver"
}
]
}
],
"source": "security@apache.org"
}
],
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "Memory allocation with excessive size value vulnerability in Apache Directory LDAP API.\n\n\n\nA malicious peer (or a MITM) can send a small BER-encoded response causing a large memory allocation before any data is received. This can lead to an OutOfMemoryError and denial of service.\n\n\n\nThe client JVM OOMs (OutOfMemoryError bypasses the DecoderException handlers) or pins the large allocation per connection while the attacker stalls.\n\n\n\nA handful of connections exhausts any heap. The same bytes from an unauthenticated pre-bind client hit any embedding server that did not set MAX_PDU_SIZE_ATTR.\n\n\n\nThis issue affects Apache Directory LDAP API: from 1.2.0 before 1.2.9.\n\n\n\nUsers are recommended to upgrade to version 1.2.9, which fixes the issue."
}
],
"id": "CVE-2026-102731",
"lastModified": "2026-10-02T14:30:28.440",
"metrics": {},
"published": "2026-10-02T10:17:04.530",
"references": [
{
"source": "security@apache.org",
"url": "https://lists.apache.org/thread.html/b8kg8881pc0v8lp59w0fcfrs69wjbqvd"
}
],
"sourceIdentifier": "security@apache.org",
"vulnStatus": "Deferred",
"weaknesses": [
{
"description": [
{
"lang": "en",
"value": "CWE-789"
}
],
"source": "security@apache.org",
"type": "Primary"
}
]
}
} | — |