CVE-2026-32327
published 2026-08-06CVE-2026-32327: A bug in APR-util version 1.6.3 (and earlier) allows a stack recursion attack against any library consumer which parses XML from untrusted sources and uses the…
PriorityP354critical9.1CVSS 3.1
AVNACLPRNUINSUCHINAH
EPSS
0.46%
38.2th percentile
A bug in APR-util version 1.6.3 (and earlier) allows a stack recursion attack against any library consumer which parses XML from untrusted sources and uses the apr_xml_quote_elem() function.
Users are recommended to upgrade to version 1.6.4, which fixes this issue.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | apr-util | < 1.6.4 | 1.6.4 |
| apache | apr-util | — | — |
| apache_software_foundation | apache_portable_runtime_utility | <= 1.6.3 | — |
CVSS provenance
nvdv3.19.1CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
vendor_redhat9.1CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
A bug in APR-util version 1.6.3 (and earlier) allows a stack recursion attack against any library consumer which parses XML from untrusted sources and uses the apr_xml_quote_elem() function.
ghsa_unreviewed·2026-08-06
CVE-2026-32327 [CRITICAL] CWE-674 A bug in APR-util version 1.6.3 (and earlier) allows a stack recursion attack against any library consumer which parses XML from untrusted sources and uses the apr_xml_quote_elem() function.
A bug in APR-util version 1.6.3 (and earlier) allows a stack recursion attack against any library consumer which parses XML from untrusted sources and uses the apr_xml_quote_elem() function.
Users are recommended to upgrade to version 1.6.4, which fixes this issue.
Red Hat
apr-util: APR-util: Denial of Service via XML stack recursion attack
vendor_redhat·2026-08-06·CVSS 9.1
CVE-2026-32327 [CRITICAL] CWE-776 apr-util: APR-util: Denial of Service via XML stack recursion attack
apr-util: APR-util: Denial of Service via XML stack recursion attack
A bug in APR-util version 1.6.3 (and earlier) allows a stack recursion attack against any library consumer which parses XML from untrusted sources and uses the apr_xml_quote_elem() function.
Users are recommended to upgrade to version 1.6.4, which fixes this issue.
A flaw was found in APR-util. A remote attacker could exploit a stack recursion vulnerability by providing specially crafted XML input to a library consumer that uses the `apr_xml_quote_elem()` function. This could lead to a denial of service (DoS) due to an application crash.
Mitigation: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-32327 apr-util: APR-util: Denial of Service via XML stack recursion attack [fedora-all]
bugzilla·2026-08-10·CVSS 9.1
CVE-2026-32327 [CRITICAL] CVE-2026-32327 apr-util: APR-util: Denial of Service via XML stack recursion attack [fedora-all]
CVE-2026-32327 apr-util: APR-util: Denial of Service via XML stack recursion attack [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
A bug in APR-util version 1.6.3 (and earlier) allows a stack recursion attack against any library consumer which parses XML from untrusted sources and uses the apr_xml_quote_elem() function.
Users are recommended to upgrade to version 1.6.4, which fixes this issue.
Discussion:
FEDORA-2026-edfb6293ee (apr-util-1.6.5-1.fc44) has been submitted as an update to Fedora 44.
https://bodhi.fedoraproject.org/updates/FEDORA-2026-edfb6293ee
---
FEDORA-2026-1ba2df871e (apr-util-1
Bugzilla
CVE-2026-32327 apr-util: APR-util: Denial of Service via XML stack recursion attack
bugzilla·2026-08-06·CVSS 9.1
CVE-2026-32327 [CRITICAL] CVE-2026-32327 apr-util: APR-util: Denial of Service via XML stack recursion attack
CVE-2026-32327 apr-util: APR-util: Denial of Service via XML stack recursion attack
A bug in APR-util version 1.6.3 (and earlier) allows a stack recursion attack against any library consumer which parses XML from untrusted sources and uses the apr_xml_quote_elem() function.
Users are recommended to upgrade to version 1.6.4, which fixes this issue.
2026-08-06
Published