CVE-2026-78243
Received Received - Intake

Apache YuniKorn LDAP Group Resolver Out of Bounds Read

Vulnerability report for CVE-2026-78243, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-07

Last updated on: 2026-10-07

Assigner: Apache Software Foundation

Description

Apache YuniKorn 1.8.0 and later, if configured with the LDAP group resolver, crashes due to an out of bounds read processing group membership entries.If the LDAP server returns a group membership entry, memberOf attribute, for a user specified in the pod the server crashesΒ if a membership record does not start with "CN=". This only affects install that have the non default LDAP group provider configured.Β  Users are recommended to upgrade to version 1.10.0, which fixes this issue.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-07
Last Modified
2026-10-07
Generated
2026-10-07
AI Q&A
2026-10-07
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
Apache Software Foundation Apache YuniKorn 1.8.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-248 An exception is thrown from a function, but it is not caught.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

Apache YuniKorn versions 1.8.0 and later have a flaw in the LDAP group resolver. When processing group membership entries, if an entry does not start with 'CN=' the system crashes due to an out of bounds read. This only affects systems using the non-default LDAP group provider configuration.

Detection Guidance

This vulnerability only affects Apache YuniKorn installations with the non-default LDAP group resolver configured. Check if your YuniKorn setup uses LDAP group resolution by reviewing configuration files for LDAP-related settings. No specific commands are provided for detection in the given context.

Impact Analysis

The vulnerability can cause Apache YuniKorn to crash when processing certain LDAP group membership entries. This may lead to service disruption for systems relying on YuniKorn for workload scheduling and resource management.

Mitigation Strategies

Upgrade Apache YuniKorn to version 1.10.0 or later to fix the issue. If upgrading is not immediately possible, disable the LDAP group resolver in your YuniKorn configuration as a temporary workaround.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-78243. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart