CVE-2026-103552: Apache Directory LDAP API: A unbound client can send a deeply nested search filter that overflows the stack in the server's decoder
Published Oct 2, 2026
·Updated
Stack Overflow vulnerability in Apache Directory LDAP API.
Before binding, a client can send a deeply nested search filter that overflows the stack in the server's decoder.
This issue affects Apache Directory LDAP API: from 1.2.0 before 1.2.9.
Users are recommended to upgrade to version 1.2.9, which fixes the issue.
Affected Software
1 affected component
Apache Directory LDAP API>=1.2.0<1.2.9
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Apache Directory LDAP APIto a version that resolves this vulnerability.Fixed in 1.2.9
Event History
Oct 2, 2026
CVE Published
via MITRE·09:48 AM
Data Sourced
via MITRE·09:48 AM
DescriptionWeakness
Data Sourced
via NVD·10:17 AM
DescriptionWeakness
Frequently Asked Questions
1
Which deployments are affected?
Apache Directory LDAP API versions from 1.2.0 through before 1.2.9 are affected.
2
Does an attacker need to authenticate first?
No. An unbound client can send the malicious deeply nested search filter before binding.
3
What is the recommended remediation?
Upgrade Apache Directory LDAP API to version 1.2.9, which fixes the issue.