CVE-2026-103552EPSS p25.4%
CVE-2026-103552CVE-2026-103552
Description
Stack Overflow vulnerability in Apache Directory LDAP API.
Before binding, a client can send a deeply nested search filter that overflows the stack in the server's decoder.
This issue affects Apache Directory LDAP API: from 1.2.0 before 1.2.9.
Users are recommended to upgrade to version 1.2.9, which fixes the issue.
Scoring
| CVSS | 7.3 () |
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L |
| EPSS | 0.34% probability of exploitation · percentile 25.4% · 2026-10-05T12:00:23Z |
| Last modified | 2026-10-02 |