Skip to content
Rota Nacional

Cyber ·

Critical flaw affects BER decoding in Apache Directory LDAP API

An advisory published on October 2, 2026 reports that a small BER response can trigger excessive memory allocation, an OutOfMemoryError, and denial of service. Versions 1.2.0 up to, but not including, 1.2.9 are affected.

A security advisory published on October 2, 2026 rates CVE-2026-102731 as critical. The flaw involves excessive memory allocation during BER decoding in the Apache Directory LDAP API. According to the report, a malicious peer or intermediary can send a small BER response that causes the client to allocate a large amount of memory before receiving data, potentially leading to an OutOfMemoryError and denial of service.

The advisory identifies versions 1.2.0 up to, but not including, 1.2.9 as affected. To confirm details and track updates, consult the original oss-sec feed advisory and compare its version range with components used by your organization; do not infer exposure from the product name alone. If using AI to analyze code, logs, or the advisory, remove personal data and secrets before submitting the material.

Get new articles

Privacy, AI engineering and security in your inbox.

Rota Nacional

Bring privacy into your workflow.

30 days, no card, with a starting quota. After that, Pix credit from R$ 5,00.

Try free