Apache · Apache Yunikorn · CVE-2026-78243
**Name of the Vulnerable Software and Affected Versions**
Apache YuniKorn versions 1.8.0 through 1.9.x
**Description**
When configured with the LDAP group resolver, the server crashes due to an out-of-bounds read while processing group membership entries. This occurs if the LDAP server returns a `memberOf` attribute for a user specified in the pod, and the membership record does not start with "CN=". This issue specifically affects installations using the non-default LDAP group provider.
**Recommendations**
Upgrade to version 1.10.0.