CVE Vulnerabilities

CVE-2026-103878

Insufficient Verification of Data Authenticity

Published: Oct 02, 2026 | Modified: Oct 02, 2026
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

Cleartext transmission of sensitive information vulnerability in Apache Directory LDAP API.

A StartTLS extended operation started after a Search request has been sent can lead to receive data in plain text before the TLS Handshake has been completed.

This issue affects Apache Directory LDAP API: from 2.1.0 before 2.1.9.

Users are recommended to upgrade to version 2.1.9, which fixes the issue.

Weakness

The product does not sufficiently verify the origin or authenticity of data, in a way that causes it to accept invalid data.

References