https://seclists.org/oss-sec/2026/q4/35: CVE-2026-103878: Apache Dictory LDAP API: Injection of plaintext sponses during StartTLS
Published Oct 2, 2026
·Updated
Affected Software
1 affected component
Apache Directory LDAP API>=2.1.0<2.1.9
Apache Directory LDAP API versions from 2.1.0 through versions before 2.1.9 are affected. The issue occurs when a StartTLS extended operation is initiated after a Search request has been sent.
Sensitive information may be received in cleartext before the TLS handshake has completed. The advisory describes this as injection of plaintext responses during StartTLS.
Upgrade Apache Directory LDAP API to version 2.1.9, which fixes the issue.