HIGH🇵🇱 Wersja polska

CVE-2025-49506

CVSS 7.5v3.1pub. 2026-08-06upd. 2026-08-07

APR-util versions 1.6.3 (and earlier) function apr_password_validate() was not constant-time with regards to hashes or passwords comparisons, potentially leaking their content via a side channel timing attack particularly on platforms without crypt() such as  Windows, BeOS, NetWare, or Android. Users are recommended to upgrade to version 1.6.4, which fixes this issue.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
  • Apache Apr Util

    APP
    Apache
    1.2.0 – 1.6.4 (excl.)
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2026-32327CRITICAL9.1PL ✓same product

APR-util: atak stack recursion przez apr_xml_quote_elem() przy parsowaniu XML

CVE-2026-34191CRITICAL9.1PL ✓same product

SQL Injection w Apache Portable Runtime Utility via apr_dbd_oracle

CVE-2026-34502HIGH7.5PL ✓same product

Heap-based Buffer Overflow w kliencie memcached Apache Portable Runtime Utility

CVE-2026-34501HIGH7.5PL ✓same product

Heap-based Buffer Overflow w kliencie Redis biblioteki Apache Portable Runtime Utility

CVE-2009-2412HIGH10.0same product

Multiple integer overflows in the Apache Portable Runtime (APR) library and the Apache Portable Utility librar...