天下漏洞,尽知其名
MEDIUM 重点关注

CVE-2026-103880 Apache Directory LDAP API 资源消耗拒绝服务漏洞

影响攻击者可触发服务器 CPU 长时间高负载,导致拒绝服务

MEDIUM
暂无 CVSS 评分
AI 研判

Apache Directory LDAP API 存在非对称资源消耗漏洞。当 LDAP 服务器使用 bcrypt 算法并以极高代价因子(如 30)存储密码时,校验凭据会使服务器 CPU 持续运行数小时。该问题影响 2.1.0 至 2.1.9 之前的版本。

影响范围

Apache Directory LDAP API

Apache Directory LDAP API 2.1.0 起至 2.1.9 之前的版本。

漏洞详情

漏洞类型为资源消耗型拒绝服务(非对称资源消耗)。成因是 API 未对 bcrypt 的代价因子设置上限,攻击者或配置方可将代价因子设为 30 等极高值。校验凭据时服务器需进行海量哈希计算,CPU 被长时间占用,从而拖垮服务。

利用条件与风险

利用前提是 LDAP 服务器支持并使用了高代价因子的 bcrypt 密码存储;实战中可造成服务不可用,属于拒绝服务风险。

修复建议

官方建议升级至 2.1.9 版本以修复该问题;临时缓解措施为限制 bcrypt 代价因子上限,暂无其他公开信息。

原始情报

Asymmetric Resource Consumption vulnerability in Apache Directory LDAP API.

Storing a password using the bcrypt algorithm with a high force like 30 in a LDAP server that supports this algorithm will cause the server CPU to  run for hours checking the credentials. A bounded cost should be enforced to avoid a server DOS.

This issue affects Apache Directory LDAP API: from 2.1.0 before 2.1.9.

Users are recommended to upgrade to version 2.1.9, which fixes the issue.