CVE-2026-78243
Received
Received - Intake
Apache YuniKorn LDAP Group Resolver Out of Bounds Read
Vulnerability report for CVE-2026-78243, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.
Publication date: 2026-10-07
Last updated on: 2026-10-07
Assigner: Apache Software Foundation
Description
Description
Apache YuniKorn 1.8.0 and later, if configured with the LDAP group resolver, crashes due to an out of bounds read processing group membership entries.If the LDAP server returns a group membership entry, memberOf attribute, for a user specified in the pod the server crashesΒ if a membership record does not start with "CN=".
This only affects install that have the non default LDAP group provider configured.Β
Users are recommended to upgrade to version 1.10.0, which fixes this issue.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| Apache | Software | Foundation Apache YuniKorn 1.8.0 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-248 | An exception is thrown from a function, but it is not caught. |