CVE-2026-103878

EUVD-2026-91378
Cleartext transmission of sensitive information vulnerability in Apache Directory LDAP API.



A StartTLS extended operation started after a Search request has been sent can lead to receive data in plain text before the TLS Handshake has been completed.



This issue affects Apache Directory LDAP API: from 2.1.0 before 2.1.9.



Users are recommended to upgrade to version 2.1.9, which fixes the issue.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
apacheCNA
UNKNOWN
---
Base Score
CVSS 3.x
EPSS Score
Percentile: Unknown
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
VendorProductVersionSource
apachedirectory_ldap_api
2.1.0 ≤
𝑥
< 2.1.9
CNA