PT-2026-107465 · Apache · Apache Yunikorn

·

CVE-2026-78243

·

Published

2026-10-07

·

Updated

2026-10-07

CVSS v4.0

2.1

Low

VectorAV:N/AC:H/AT:P/PR:L/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:L/S:N/AU:N/R:A/V:D/RE:H/U:Green
Name of the Vulnerable Software and Affected Versions Apache YuniKorn versions 1.8.0 through 1.9.x
Description When configured with the LDAP group resolver, the server crashes due to an out-of-bounds read while processing group membership entries. This occurs if the LDAP server returns a memberOf attribute for a user specified in the pod, and the membership record does not start with "CN=". This issue specifically affects installations using the non-default LDAP group provider.
Recommendations Upgrade to version 1.10.0.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-78243

Affected Products

Apache Yunikorn