A malicious peer (or a MITM) can send a small BER-encoded response causing a large memory allocation before any data is received. This can lead to an OutOfMemoryError and denial of service.
The client JVM OOMs (OutOfMemoryError bypasses the DecoderException handlers) or pins the large allocation per connection while the attacker stalls.
A handful of connections exhausts any heap. The same bytes from an unauthenticated pre-bind client hit any embedding server that did not set MAX_PDU_SIZE_ATTR.
This issue affects Apache Directory LDAP API: from 1.2.0 before 1.2.9.
Users are recommended to upgrade to version 1.2.9, which fixes the issue.
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 02 Oct 2026 10:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Apache
Apache directory Ldap Api |
|
| Vendors & Products |
Apache
Apache directory Ldap Api |
Fri, 02 Oct 2026 09:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Memory allocation with excessive size value vulnerability in Apache Directory LDAP API. A malicious peer (or a MITM) can send a small BER-encoded response causing a large memory allocation before any data is received. This can lead to an OutOfMemoryError and denial of service. The client JVM OOMs (OutOfMemoryError bypasses the DecoderException handlers) or pins the large allocation per connection while the attacker stalls. A handful of connections exhausts any heap. The same bytes from an unauthenticated pre-bind client hit any embedding server that did not set MAX_PDU_SIZE_ATTR. This issue affects Apache Directory LDAP API: from 1.2.0 before 1.2.9. Users are recommended to upgrade to version 1.2.9, which fixes the issue. | |
| Title | Apache Directory LDAP API: Denial of service via excessive memory allocation in BER decode | |
| Weaknesses | CWE-789 | |
| References |
|
Status: PUBLISHED
Assigner: apache
Published:
Updated: 2026-10-02T09:22:00.813Z
Reserved: 2026-09-29T16:17:56.332Z
Link: CVE-2026-102731
No data.
Status : Received
Published: 2026-10-02T10:17:04.530
Modified: 2026-10-02T10:17:04.530
Link: CVE-2026-102731
No data.
OpenCVE Enrichment
Updated: 2026-10-02T10:30:07Z
-
CWE-789
Memory Allocation with Excessive Size Value