Apache Directory LDAP API flaw can cause denial of service
An advisory published on October 2, 2026, rates a resource-consumption flaw in the Apache Directory LDAP API as important. Verifying bcrypt passwords with a high cost factor can keep CPU busy for hours.
The advisory, published on October 2, 2026 and rated important, describes CVE-2026-103880 in the Apache Directory LDAP API. Affected versions are 2.1.0 through releases earlier than 2.1.9.
According to the report, passwords stored with bcrypt and a high cost factor—such as 30—can make an LDAP server's CPU work for hours while checking credentials. This may cause denial of service; the advisory recommends setting a limit on the cost factor. Consult the original oss-sec mailing-list post and confirm the affected versions and guidance in the project's official channels before taking action.