CVE-2026-103880 Apache Directory LDAP API 资源消耗拒绝服务漏洞
影响攻击者可触发服务器 CPU 长时间高负载,导致拒绝服务
Apache Directory LDAP API 存在非对称资源消耗漏洞。当 LDAP 服务器使用 bcrypt 算法并以极高代价因子(如 30)存储密码时,校验凭据会使服务器 CPU 持续运行数小时。该问题影响 2.1.0 至 2.1.9 之前的版本。
影响范围
Apache Directory LDAP API 2.1.0 起至 2.1.9 之前的版本。
漏洞详情
漏洞类型为资源消耗型拒绝服务(非对称资源消耗)。成因是 API 未对 bcrypt 的代价因子设置上限,攻击者或配置方可将代价因子设为 30 等极高值。校验凭据时服务器需进行海量哈希计算,CPU 被长时间占用,从而拖垮服务。
利用条件与风险
利用前提是 LDAP 服务器支持并使用了高代价因子的 bcrypt 密码存储;实战中可造成服务不可用,属于拒绝服务风险。
修复建议
官方建议升级至 2.1.9 版本以修复该问题;临时缓解措施为限制 bcrypt 代价因子上限,暂无其他公开信息。
Asymmetric Resource Consumption vulnerability in Apache Directory LDAP API.
Storing a password using the bcrypt algorithm with a high force like 30 in a LDAP server that supports this algorithm will cause the server CPU to run for hours checking the credentials. A bounded cost should be enforced to avoid a server DOS.
This issue affects Apache Directory LDAP API: from 2.1.0 before 2.1.9.
Users are recommended to upgrade to version 2.1.9, which fixes the issue.