← Advisories

Apache Karaf 4.4.11 JAAS LDAP Login Modules LDAP Filter Injection

Medium
Advisory ID
ZSL-2026-6006
Release Date
28 September 2026
Vendor
The Apache Software Foundation
Affected Version
4.4.11
Tested On
org.apache.karaf.jaas.modules-4.4.11.jar (Maven Central), Apache Karaf JAAS LDAP login module, Eclipse Temurin OpenJDK 21.0.6 (LTS), UnboundID LDAP SDK for Java 7.0.1, Microsoft Windows 10
Summary

Karaf is a lightweight, powerful, and enterprise ready modulith runtime. It provides all the ecosystem and bootstrapping options you need for your applications.

Description

Apache Karaf's JAAS LDAP login module is affected by LDAP filter injection. The user and role LDAP search filters are built in LDAPCache by string substitution: each placeholder (%u for the username, %dn for the user DN, %fqdn for the fully qualified DN) is inserted with java.util.regex Matcher.quoteReplacement followed by doubling backslashes, which is regex-replacement escaping, not RFC 2254 / RFC 4515 LDAP filter escaping. The filter construction itself therefore does not neutralize LDAP metacharacters, it relies on the caller to have encoded the values. The login module does pre-encode the username with Util.doRFC2254Encoding before the user search, but the role search filter also substitutes the DN values (%dn, %fqdn) with no LDAP escaping, and the filter builder performs none of its own. As a result a value that reaches the filter without prior encoding is not neutralized and can alter the LDAP query.

Proof of Concept
Disclosure Timeline
13.08.2026Vulnerability discovered.
18.08.2026Contact with the vendor.
19.08.2026Vendor forwards details to appropriate PMC.
10.09.2026Vendor confirms the vulnerability.
22.09.2026Vendor releases version 4.4.12 to address this issue.
28.09.2026Coordinated public security advisory released.
Credits
Vulnerability discovered by Gjoko Krstic
High five to JB!
References
Changelog
28.09.2026Initial release