PatchSiren cyber security CVE debrief
CVE-2026-78243 Apache Software Foundation CVE debrief
Apache YuniKorn 1.8.0 and later, if configured with the LDAP group resolver, crashes due to an out of bounds read processing group membership entries. This issue arises when the LDAP server returns a group membership entry with a memberOf attribute for a user specified in the pod, causing the server to crash if the membership record does not start with 'CN='. Users are recommended to upgrade to version 1.10.0, which fixes this issue. The crash occurs due to improper handling of lowercase attribute names, affecting installations with the non-default LDAP group provider configured.
- Vendor
- Apache Software Foundation
- Product
- Apache YuniKorn
- CVSS
- LOW 2.1
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-07
- Original CVE updated
- 2026-10-07
- Advisory published
- 2026-10-07
- Advisory updated
- 2026-10-07
Who should care
Defenders and administrators of Apache YuniKorn installations with LDAP group resolver configured should assess exposure and prioritize upgrading to version 1.10.0. This vulnerability affects operators, platforms, and security teams managing Apache YuniKorn deployments. The impact includes potential crashes and the need for upgrades to prevent exploitation.
Why it matters
Defenders should care about CVE-2026-78243 as it affects Apache YuniKorn installations with LDAP group resolver configured, potentially causing crashes. Upgrading to version 1.10.0 is recommended.
- Potential crashes due to out of bounds read
- Need to upgrade to version 1.10.0 for fix
- Limited information available on exploitation or impact
Technical summary
Apache YuniKorn 1.8.0 and later, if configured with the LDAP group resolver, crashes due to an out of bounds read processing group membership entries. This only affects installations with the non-default LDAP group provider configured. The crash occurs when the LDAP server returns a group membership entry with a memberOf attribute that does not start with 'CN='. The issue is caused by improper handling of lowercase attribute names. Upgrading to version 1.10.0 fixes this issue. Defenders should assess exposure and prioritize upgrading.
Defensive priority
Upgrade to version 1.10.0, assess exposure, and verify remediation
Recommended defensive actions
- Upgrade Apache YuniKorn to version 1.10.0
- Assess exposure and verify remediation
- Monitor for potential crashes
- Review compensating controls for exposed systems
- Check relevant monitoring, detection, and logs for exposed assets
- Track exceptions and retest remediated assets
- Confirm whether affected product deployments exist in managed environments
Evidence notes
The CVE record and source item provide details on the vulnerability, but limited information is available on exploitation or impact. The issue is caused by an out-of-bounds read when processing group membership entries with lowercase attribute names. Defenders should verify the affected scope and upgrade to version 1.10.0. The CVE Program record and NIST NVD detail page offer additional information.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-78243 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-78243
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-78243 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-78243
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Apache YuniKorn: LDAP Group provider panics on lowercase attribute name
Unverified legacy reference
URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/78xxx/CVE-2026-78243.json
cve_program_cvelist_v5
-
Source reference
Unverified legacy reference
URL: https://lists.apache.org/thread.html/yz51lpj6k8q2hz7x2gjdpcrk44hdn25v
Supplemental source - vendor-advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.