https://seclists.org/oss-sec/2026/q4/37: CVE-2026-103885: Apache Dictory LDAP API: Denial of service via crafted telephone number values
Published Oct 2, 2026
·Updated
Affected Software
1 affected component
Apache Directory LDAP API>=2.1.0<2.1.9
LDAP servers that use Apache Directory LDAP API are affected, including examples such as Apache DS, when running versions from 2.1.0 before 2.1.9.
The server must process a badly crafted Telephone Number value. Processing that value can cause the server to consume 100% of a CPU core indefinitely.
Upgrade Apache Directory LDAP API to version 2.1.9, which fixes the issue.