Skip to content
Rota Nacional

Cyber ·

Apache Directory LDAP API flaw can cause denial of service

An advisory published on October 2, 2026, rates a resource-consumption flaw in the Apache Directory LDAP API as important. Verifying bcrypt passwords with a high cost factor can keep CPU busy for hours.

The advisory, published on October 2, 2026 and rated important, describes CVE-2026-103880 in the Apache Directory LDAP API. Affected versions are 2.1.0 through releases earlier than 2.1.9.

According to the report, passwords stored with bcrypt and a high cost factor—such as 30—can make an LDAP server's CPU work for hours while checking credentials. This may cause denial of service; the advisory recommends setting a limit on the cost factor. Consult the original oss-sec mailing-list post and confirm the affected versions and guidance in the project's official channels before taking action.

Get new articles

Privacy, AI engineering and security in your inbox.

Rota Nacional

Bring privacy into your workflow.

30 days, no card, with a starting quota. After that, Pix credit from R$ 5,00.

Try free