VendorsApachedirectory_ldap_apiall versions
Vulnerabilities

Apache Directory LDAP API

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

3CVEs
CVE-2018-1337
In Apache Directory LDAP API before 1.0.2, a bug in the way the SSL Filter was setup made it possible for another thread to use the connection before the TLS layer has been established, if the connection has already been used and put back in a pool of connections, leading to leaking any information contained in this request (including the credentials when sending a BIND request).
Published 2018-07-10 · Modified
9.8EPSS 0.052
CVE-2026-35563
Apache Directory LDAP API: LDAP client implementation does not verify if the server certificate matches the intended LDAP hostname
Published 2026-06-01 · Analyzed
8.8EPSS 0.003
CVE-2015-3250
Apache Directory LDAP API before 1.0.0-M31 allows attackers to conduct timing attacks via unspecified vectors.
Published 2017-09-07 · Modified
7.5EPSS 0.051