CVE-2025-49506
published 2026-08-06CVE-2025-49506: APR-util versions 1.6.3 (and earlier) function apr_password_validate() was not constant-time with regards to hashes or passwords comparisons, potentially…
PriorityP344high7.5CVSS 3.1
AVNACLPRNUINSUCHINAN
EPSS
0.38%
31.0th percentile
APR-util versions 1.6.3 (and earlier) function apr_password_validate() was not constant-time with regards to hashes or passwords comparisons, potentially leaking their content via a side channel timing attack particularly on platforms without crypt() such as Windows, BeOS, NetWare, or Android.
Users are recommended to upgrade to version 1.6.4, which fixes this issue.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | apr-util | — | — |
| apache | apr-util | >= 1.2.0 < 1.6.4 | 1.6.4 |
| apache_software_foundation | apache_portable_runtime_utility | 1.2.0 – 1.6.3 | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
APR-util versions 1.6.3 (and earlier) function apr_password_validate() was not constant-time with regards to hashes or passwords comparisons, potentially leaking their content via a side channel timin
ghsa_unreviewed·2026-08-06
CVE-2025-49506 [HIGH] CWE-208 APR-util versions 1.6.3 (and earlier) function apr_password_validate() was not constant-time with regards to hashes or passwords comparisons, potentially leaking their content via a side channel timin
APR-util versions 1.6.3 (and earlier) function apr_password_validate() was not constant-time with regards to hashes or passwords comparisons, potentially leaking their content via a side channel timing attack particularly on platforms without crypt() such as Windows, BeOS, NetWare, or Android.
Users are recommended to upgrade to version 1.6.4, which fixes this issue.
Red Hat
apr-util: Apache Portable Runtime Utility: Information disclosure via timing attack in password validation
vendor_redhat·2026-08-06·CVSS 7.5
CVE-2025-49506 [HIGH] CWE-208 apr-util: Apache Portable Runtime Utility: Information disclosure via timing attack in password validation
apr-util: Apache Portable Runtime Utility: Information disclosure via timing attack in password validation
APR-util versions 1.6.3 (and earlier) function apr_password_validate() was not constant-time with regards to hashes or passwords comparisons, potentially leaking their content via a side channel timing attack particularly on platforms without crypt() such as Windows, BeOS, NetWare, or Android.
Users are recommended to upgrade to version 1.6.4, which fixes this issue.
A flaw was found in Apache Portable Runtime Utility (apr-util). The `apr_password_validate()` function does not perform constant-time comparisons for hashes or passwords. This vulnerability allows a remote attacker to conduct a timing attack, particularly on platforms without `crypt()` such as Windows, BeOS, NetWare, or
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2025-49506 apr-util: Apache Portable Runtime Utility: Information disclosure via timing attack in password validation [fedora-all]
bugzilla·2026-08-11·CVSS 7.5
CVE-2025-49506 [HIGH] CVE-2025-49506 apr-util: Apache Portable Runtime Utility: Information disclosure via timing attack in password validation [fedora-all]
CVE-2025-49506 apr-util: Apache Portable Runtime Utility: Information disclosure via timing attack in password validation [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
APR-util versions 1.6.3 (and earlier) function apr_password_validate() was not constant-time with regards to hashes or passwords comparisons, potentially leaking their content via a side channel timing attack particularly on platforms without crypt() such as Windows, BeOS, NetWare, or Android.
Users are recommended to upgrade to version 1.6.4, which fixes this issue.
Bugzilla
CVE-2025-49506 apr-util: Apache Portable Runtime Utility: Information disclosure via timing attack in password validation
bugzilla·2026-08-06·CVSS 7.5
CVE-2025-49506 [HIGH] CVE-2025-49506 apr-util: Apache Portable Runtime Utility: Information disclosure via timing attack in password validation
CVE-2025-49506 apr-util: Apache Portable Runtime Utility: Information disclosure via timing attack in password validation
APR-util versions 1.6.3 (and earlier) function apr_password_validate() was not constant-time with regards to hashes or passwords comparisons, potentially leaking their content via a side channel timing attack particularly on platforms without crypt() such as Windows, BeOS, NetWare, or Android.
Users are recommended to upgrade to version 1.6.4, which fixes this issue.
2026-08-06
Published