Vulnerabilities
Vulnerable Software
Apache:  >> Apr-Util  >> 1.5.0  Security Vulnerabilities
A bug in APR-util version 1.6.3 (and earlier) allows a stack recursion attack against any library consumer which parses XML from untrusted sources and uses the apr_xml_quote_elem() function. Users are recommended to upgrade to version 1.6.4, which fixes this issue.
CVSS Score
9.1
EPSS Score
0.005
Published
2026-08-06
Heap-based Buffer Overflow vulnerability in Apache Portable Runtime Utility memcached client This issue affects Apache Portable Runtime Utility: from 1.3.0 through 1.6.3.
CVSS Score
7.5
EPSS Score
0.005
Published
2026-08-06
APR-util versions 1.6.3 (and earlier) function apr_password_validate() was not constant-time with regards to hashes or passwords comparisons, potentially leaking their content via a side channel timing attack particularly on platforms without crypt() such as  Windows, BeOS, NetWare, or Android. Users are recommended to upgrade to version 1.6.4, which fixes this issue.
CVSS Score
7.5
EPSS Score
0.004
Published
2026-08-06


Contact Us

Shodan ® - All rights reserved