CVE-2026-103880
N/A
N/A
Summary
Asymmetric Resource Consumption vulnerability in Apache Directory LDAP API.
Storing a password using the bcrypt algorithm with a high force like 30 in a LDAP server that supports this algorithm will cause the server CPU to run for hours checking the credentials. A bounded cost should be enforced to avoid a server DOS.
This issue affects Apache Directory LDAP API: from 2.1.0 before 2.1.9.
Users are recommended to upgrade to version 2.1.9, which fixes the issue.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Apache Software Foundation | Apache Directory LDAP API | 2.1.0 < 2.1.9 | affected |
Weaknesses
- CWE-405: CWE-405 Asymmetric Resource Consumption (Amplification)
ADP Enrichment
CVE Program Container
Additional References
References
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.