Critical Apache Directory LDAP API flaw can cause stack overflow
A security notice published on October 2, 2026 reports that deeply nested LDAP search filters can cause a stack overflow before authentication. Versions 1.2.0 through releases earlier than 1.2.9 are affected.
A security notice published on October 2, 2026 rates a stack overflow vulnerability in the Apache Directory LDAP API as critical. According to the notice, an unauthenticated client can send a deeply nested search filter and trigger the issue in the server decoder. Versions 1.2.0 through releases earlier than 1.2.9 are affected; the stated recommendation is to upgrade to version 1.2.9.
The content was automatically translated from a post in the oss-sec feed. To confirm the scope, severity, and fix, consult the original post in the feed and official Apache Directory project information. Also check which versions are in use before planning an upgrade.