cbcvebase.

Apache Software Foundation Apache Portable Runtime Utility vulnerabilities

6 known vulnerabilities affecting apache_software_foundation/apache_portable_runtime_utility.

Total CVEs
6
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL2HIGH3MEDIUM1

Vulnerabilities

Page 1 of 1
CVE-2026-34191P2CRITICALCVSS 9.1≥ 1.6.0, ≤ 1.6.32026-08-06
CVE-2026-34191 [CRITICAL] CWE-89 CVE-2026-34191: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability i Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Portable Runtime Utility via apr_dbd_oracle provider. This issue affects Apache Portable Runtime Utility: from 1.6.0 through 1.6.3
nvd
CVE-2026-32327P3CRITICALCVSS 9.1≤ 1.6.32026-08-06
CVE-2026-32327 [CRITICAL] CWE-674 CVE-2026-32327: A bug in APR-util version 1.6.3 (and earlier) allows a stack recursion attack against any library co A bug in APR-util version 1.6.3 (and earlier) allows a stack recursion attack against any library consumer which parses XML from untrusted sources and uses the apr_xml_quote_elem() function. Users are recommended to upgrade to version 1.6.4, which fixes this issue.
nvd
CVE-2026-34502P3HIGHCVSS 7.5≥ 1.3.0, ≤ 1.6.32026-08-06
CVE-2026-34502 [HIGH] CWE-122 CVE-2026-34502: Heap-based Buffer Overflow vulnerability in Apache Portable Runtime Utility memcached client This i Heap-based Buffer Overflow vulnerability in Apache Portable Runtime Utility memcached client This issue affects Apache Portable Runtime Utility: from 1.3.0 through 1.6.3.
nvd
CVE-2026-34501P3HIGHCVSS 7.5≥ 1.6.0, ≤ 1.6.32026-08-06
CVE-2026-34501 [HIGH] CWE-122 CVE-2026-34501: Heap-based Buffer Overflow vulnerability in Apache Portable Runtime Utility redis client. This issu Heap-based Buffer Overflow vulnerability in Apache Portable Runtime Utility redis client. This issue affects Apache Portable Runtime Utility: from 1.6.0 through 1.6.3. Users are recommended to upgrade to version 1.6.4, which fixes the issue.
nvd
CVE-2025-49506P3HIGHCVSS 7.5≥ 1.2.0, ≤ 1.6.32026-08-06
CVE-2025-49506 [HIGH] CWE-208 CVE-2025-49506: APR-util versions 1.6.3 (and earlier) function apr_password_validate() was not constant-time with re APR-util versions 1.6.3 (and earlier) function apr_password_validate() was not constant-time with regards to hashes or passwords comparisons, potentially leaking their content via a side channel timing attack particularly on platforms without crypt() such as Windows, BeOS, NetWare, or Android. Users are recommended to upgrade to version 1.6.4, which
nvd
CVE-2022-25147P4MEDIUMCVSS 6.5≤ 1.6.12023-01-31
CVE-2022-25147 [MEDIUM] CWE-190 CVE-2022-25147: Integer Overflow or Wraparound vulnerability in apr_base64 functions of Apache Portable Runtime Util Integer Overflow or Wraparound vulnerability in apr_base64 functions of Apache Portable Runtime Utility (APR-util) allows an attacker to write beyond bounds of a buffer. This issue affects Apache Portable Runtime Utility (APR-util) 1.6.1 and prior versions.
nvd
Apache Software Foundation Apache Portable Runtime Utility vulnerabilities | cvebase