CVE-2026-35563: Apache Directory LDAP API: LDAP client implementation does not verify if the server certificate matches the intended LDAP hostname
It was identified that the LDAP client implementation in version 2.1.7 does not verify if the server certificate matches the intended LDAP hostname. While the underlying code validates the certificate chain against a trusted authority, the absence of endpoint identification allows a valid certificate issued for an entirely unrelated host to be improperly accepted. This oversight leaves the connection highly vulnerable to server impersonation and complete connection compromise.
The root cause of this vulnerability lies in the incomplete TLS server identity verification within the LDAP client implementation.
The attacker requires MITM capability on the network to exploit this vulnerability. This attacker must be able to present a certificate trusted by the client's configured trust store.
The hostname verification has been enforced in the new version of the LDAP API
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Apache Directory LDAP APIto a version that resolves this vulnerability.Fixed in 2.1.7Patch CVE-2026-35563
Event History
Frequently Asked Questions
What is the severity of CVE-2026-35563?
CVE-2026-35563 has a severity score of high at 8.8 according to CVSS.
How do I fix CVE-2026-35563?
To mitigate CVE-2026-35563, ensure that the LDAP client implementation is updated to a version that verifies if the server certificate matches the intended LDAP hostname.
What vulnerabilities are associated with CVE-2026-35563?
CVE-2026-35563 allows for potential man-in-the-middle attacks due to the LDAP client not verifying the server certificate against its hostname.
What are the risks of not addressing CVE-2026-35563?
Failure to address CVE-2026-35563 can lead to unauthorized access or data interception due to the lack of proper certificate verification in LDAP communications.
Which versions of the software are affected by CVE-2026-35563?
CVE-2026-35563 affects Apache Directory LDAP API version 2.1.7.