7.5
CVE-2026-103885
- EPSS 0.2%
- Veröffentlicht 02.10.2026 10:17:06
- Zuletzt bearbeitet 08.10.2026 13:17:12
- Erkennungen
Apache Directory LDAP API: Denial of service via crafted telephone number values
Asymmetric Resource Consumption vulnerability in Apache Directory LDAP API. A LDAP server using the LDAP API (like Apache DS) may consume 100% of a CPU core indefinitely when processing some badly crafted Telephone Numbers. This issue affects Apache Directory LDAP API: from 2.1.0 before 2.1.9. Users are recommended to upgrade to version 2.1.9, which fixes the issue.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerApache Software Foundation
≫
Produkt
Apache Directory LDAP API
Default Statusunaffected
Version
2.1.0
Version <
2.1.9
Status
affected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.2% | 0.086 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| CISA-ADP | 7.5 | 3.9 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
|
CWE-400 Uncontrolled Resource Consumption
The product does not properly control the allocation and maintenance of a limited resource.
https://lists.apache.org/thread.html/wjt9p1l123v6b3zd5dg41f8lfrgy5vg9
http://www.openwall.com/lists/oss-security/2026/10/02/8