https://seclists.org/oss-sec/2026/q4/34: CVE-2026-103877: Apache Dictory LDAP API: Unsafe loading of Java code from LDAP schema elements
Published Oct 2, 2026
·Updated
Affected Software
1 affected component
Apache Directory LDAP API>=2.1.0<2.1.9
Applications using Apache Directory LDAP API versions 2.1.0 through 2.1.8 are affected when they load LDAP schema data with loadSchema(). The risk applies when the LDAP server is rogue or compromised, or when an attacker can intercept the connection before TLS is established.
The attacker must control the LDAP server's response to the client's subschema search, either by operating or compromising the LDAP server or by performing a pre-TLS man-in-the-middle attack. The response must include a schema object containing a serialized Java class.
Upgrade Apache Directory LDAP API to version 2.1.9, which fixes the issue.