CVE-2026-103552: stack overflow in Apache Directory LDAP API
Apache Directory LDAP API has a stack-based buffer overflow tracked as CVE-2026-103552 with a CVSS v3 score of 7.3: a deeply nested LDAP filter overflows the stack without authentication. The fix ships in version 1.2.9, affecting the 1.2.0–1.2.8 and 2.1.0–2.1.8 branches.
- CVSS 7.3, CWE-121 stack-based buffer overflow
- No credentials needed: one nested filter triggers it
- Fixed in 1.2.9; affects 1.2.0–1.2.8 and 2.1.0–2.1.8
- ZoomEye found 154 publicly reachable ApacheDS instances
Read next
Security