MinorCritical vulnerability
CVE-2026-103552 (CVSS 7.3)
NVD · officialPublished Oct 2, 2026Risk 23/100EPSS 0.3%
Stack Overflow vulnerability in Apache Directory LDAP API. Before binding, a client can send a deeply nested search filter that overflows the stack in the server's decoder. This issue affects Apache Directory LDAP API: from 1.2.0 before 1.2.9. Users are recommended to upgrade to version 1.2.9, which fixes the issue.
Technical details
CVSS
7.3
AV:NetworkAC:LowPR:NoneUI:NoneC:LowI:LowA:Low
Evidence and sources
This record is attributed to NVD. Exploitation status and remediation guidance are kept separate from the vulnerability's technical severity.
Open primary source