CVE-2026-103878: Apache Directory LDAP API: Injection of plaintext responses during StartTLS
Cleartext transmission of sensitive information vulnerability in Apache Directory LDAP API.
A StartTLS extended operation started after a Search request has been sent can lead to receive data in plain text before the TLS Handshake has been completed.
This issue affects Apache Directory LDAP API: from 2.1.0 before 2.1.9.
Users are recommended to upgrade to version 2.1.9, which fixes the issue.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Apache Directory LDAP APIto a version that resolves this vulnerability.Fixed in 2.1.9
Event History
Frequently Asked Questions
Which deployments are affected?
Apache Directory LDAP API versions from 2.1.0 up to, but not including, 2.1.9 are affected. Version 2.1.9 contains the fix.
What sequence is required for exposure?
The issue occurs when a StartTLS extended operation is initiated after a Search request has already been sent. In that sequence, data can be received in plaintext before the TLS handshake completes.
What should teams do if they use an affected version?
Upgrade Apache Directory LDAP API to version 2.1.9. The provided information does not specify an alternative mitigation for environments that cannot immediately upgrade.