Skip to content
Rota Nacional

Cyber ·

CVE-2026-103885: flaw in Apache LDAP API

A security notice published on October 2, 2026 reports that malformed phone numbers can cause indefinite CPU consumption in the Apache Directory LDAP API. Versions from 2.1.0 up to, but not including, 2.1.9 are affected.

A security notice rated important describes an asymmetric resource-consumption vulnerability in the Apache Directory LDAP API. When processing certain malformed phone numbers, an LDAP server using the API—such as Apache DS—may keep one CPU core busy indefinitely.

The notice says API versions from 2.1.0 up to, but not including, 2.1.9 are affected, and recommends upgrading to 2.1.9. Consult the original advisory in the public oss-sec archive and check your installed version and the project's guidance before planning an upgrade. If you use AI to review the notice or prepare the change, do not submit configurations, logs, or personal data without applying your organization's data-protection policy.

Get new articles

Privacy, AI engineering and security in your inbox.

Rota Nacional

Bring privacy into your workflow.

30 days, no card, with a starting quota. After that, Pix credit from R$ 5,00.

Try free