Apache YuniKorn 1.8+ LDAP Group Resolver OOB Read Crash (Fixed 1.10.0)
CVE-2026-78243 Published on October 7, 2026
Apache YuniKorn: LDAP Group provider panics on lowercase attribute name
Apache YuniKorn 1.8.0 and later, if configured with the LDAP group resolver, crashes due to an out of bounds read processing group membership entries.If the LDAP server returns a group membership entry, memberOf attribute, for a user specified in the pod the server crashes if a membership record does not start with "CN=".
This only affects install that have the non default LDAP group provider configured.
Users are recommended to upgrade to version 1.10.0, which fixes this issue.
Vulnerability Analysis
CVE-2026-78243 can be exploited with network access. This vulnerability is consided to have a high level of attack complexity. The potential impact of an exploit of this vulnerability is considered to have no impact on confidentiality and integrity and availability.
Weakness Type
Uncaught Exception
An exception is thrown from a function, but it is not caught. When an exception is not caught, it may cause the program to crash or expose sensitive information.
Affected Versions
Apache Software Foundation Apache YuniKorn:- Version 1.8.0 and below 1.10.0 is affected.