Alert: Apache LDAP StartTLS may expose cleartext data
An advisory published on October 2, 2026 says Apache Directory LDAP API versions 2.1.0 through releases earlier than 2.1.9 may receive cleartext data when StartTLS begins after a search.
Advisory CVE-2026-103878, published on October 2, 2026 and rated important, describes a possible sensitive-information exposure in Apache Directory LDAP API. An extended StartTLS operation initiated after a Search request is sent may lead to cleartext responses being received before the TLS handshake completes.
The reported affected range is version 2.1.0 through releases earlier than 2.1.9. Administrators should check the version in use and consult the original oss-sec advisory and Apache's official channels to confirm details and remediation. Do not treat a connection as TLS-protected before the handshake has completed.