CVE-2026-103880: Apache Directory LDAP API: Denial of service via excessive bcrypt cost factor in stored passwords
Asymmetric Resource Consumption vulnerability in Apache Directory LDAP API.
Storing a password using the bcrypt algorithm with a high force like 30 in a LDAP server that supports this algorithm will cause the server CPU to run for hours checking the credentials. A bounded cost should be enforced to avoid a server DOS.
This issue affects Apache Directory LDAP API: from 2.1.0 before 2.1.9.
Users are recommended to upgrade to version 2.1.9, which fixes the issue.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Apache Directory LDAP APIto a version that resolves this vulnerability.Fixed in 2.1.9
Event History
Frequently Asked Questions
What conditions are required for this issue to cause a denial of service?
The LDAP server must support bcrypt password storage, and a password must be stored with an excessively high bcrypt cost factor, such as 30. When credentials are checked against that password, the server can consume CPU for hours.
Which deployments are affected?
Apache Directory LDAP API versions from 2.1.0 before 2.1.9 are affected. The issue is relevant where bcrypt is supported and high-cost bcrypt password values can be stored.
What should be done if upgrading cannot happen immediately?
Enforce a bounded bcrypt cost factor so passwords cannot be stored with excessively high values. This prevents credential verification from imposing hours of CPU work on the server.
What version fixes the issue?
Upgrade to Apache Directory LDAP API version 2.1.9.