PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-103885 Apache Software Foundation CVE debrief

The Apache Directory LDAP API is vulnerable to a Denial of Service (DoS) attack due to an Asymmetric Resource Consumption issue. This vulnerability occurs when the LDAP API processes badly crafted telephone number values, potentially causing a LDAP server to consume 100% of a CPU core indefinitely. This issue affects Apache Directory LDAP API versions from 2.1.0 before 2.1.9. LDAP administrators and security teams should assess exposure and prioritize remediation to prevent potential denial of service via crafted telephone number values.

Vendor
Apache Software Foundation
Product
Apache Directory LDAP API
CVSS
Unknown
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-02
Original CVE updated
2026-10-07
Advisory published
2026-10-02
Advisory updated
2026-10-07

Who should care

LDAP administrators, Apache Directory LDAP API users, and security teams responsible for monitoring and patching software vulnerabilities should assess exposure and prioritize remediation.

Why it matters

This vulnerability in Apache Directory LDAP API can lead to denial of service via crafted telephone number values. LDAP administrators and security teams should assess exposure, prioritize remediation, and monitor for unusual CPU consumption patterns.

  • Potential for denial of service due to excessive CPU consumption
  • Need for verification of affected versions and exposure
  • Priority for upgrading to version 2.1.9 or later
  • Importance of monitoring CPU usage patterns for LDAP servers

Technical summary

The Apache Directory LDAP API is vulnerable to an Asymmetric Resource Consumption issue. A LDAP server using the LDAP API may consume 100% of a CPU core indefinitely when processing some badly crafted Telephone Numbers. This issue affects Apache Directory LDAP API versions from 2.1.0 before 2.1.9. The vulnerability can be mitigated by upgrading to version 2.1.9 or later, reviewing and limiting telephone number input values, and monitoring for unusual CPU consumption patterns. It is essential to assess exposure and prioritize remediation to prevent potential denial of service via crafted telephone number values.

Defensive priority

Medium

Recommended defensive actions

  • Upgrade Apache Directory LDAP API to version 2.1.9 or later
  • Review and limit telephone number input values
  • Monitor for unusual CPU consumption patterns
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up

Evidence notes

The CVE record and source item indicate an Asymmetric Resource Consumption vulnerability in Apache Directory LDAP API, potentially causing denial of service via crafted telephone number values. Affected versions are from 2.1.0 before 2.1.9.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-103885 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-103885

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-103885 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-103885

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.