CVE-2026-78243EPSS p19.7%

CVE-2026-78243CVE-2026-78243

Description

Apache YuniKorn 1.8.0 and later, if configured with the LDAP group resolver, crashes due to an out of bounds read processing group membership entries.If the LDAP server returns a group membership entry, memberOf attribute, for a user specified in the pod the server crashes if a membership record does not start with "CN=". This only affects install that have the non default LDAP group provider configured.  Users are recommended to upgrade to version 1.10.0, which fixes this issue.

Scoring

EPSS0.29% probability of exploitation · percentile 19.7% · 2026-10-10T12:00:23Z
Last modified2026-10-07
Sourced from NVD + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.