Skip to content
Rota Nacional

Cyber ·

Alert: Apache LDAP StartTLS may expose cleartext data

An advisory published on October 2, 2026 says Apache Directory LDAP API versions 2.1.0 through releases earlier than 2.1.9 may receive cleartext data when StartTLS begins after a search.

Advisory CVE-2026-103878, published on October 2, 2026 and rated important, describes a possible sensitive-information exposure in Apache Directory LDAP API. An extended StartTLS operation initiated after a Search request is sent may lead to cleartext responses being received before the TLS handshake completes.

The reported affected range is version 2.1.0 through releases earlier than 2.1.9. Administrators should check the version in use and consult the original oss-sec advisory and Apache's official channels to confirm details and remediation. Do not treat a connection as TLS-protected before the handshake has completed.

Get new articles

Privacy, AI engineering and security in your inbox.

Rota Nacional

Bring privacy into your workflow.

30 days, no card, with a starting quota. After that, Pix credit from R$ 5,00.

Try free