🔐 CVE Alert

CVE-2026-32327

UNKNOWN 0.0

Apache Portable Runtime Utility: apr-util XML stack recursion crash

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

A bug in APR-util version 1.6.3 (and earlier) allows a stack recursion attack against any library consumer which parses XML from untrusted sources and uses the apr_xml_quote_elem() function. Users are recommended to upgrade to version 1.6.4, which fixes this issue.

CWE CWE-674
Vendor apache software foundation
Product apache portable runtime utility
Published Aug 6, 2026
Stay Ahead of the Next One

Get instant alerts for apache software foundation apache portable runtime utility

Be the first to know when new unknown vulnerabilities affecting apache software foundation apache portable runtime utility are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

Affected Versions

Apache Software Foundation / Apache Portable Runtime Utility
0 ≤ 1.6.3

References

NVD ↗ CVE.org ↗ EPSS Data ↗
lists.apache.org: https://lists.apache.org/thread/hq27vj8yfno9tkwv0fpj6jksfzgxvth1

Credits

Younghyo Cho @ CISLab, SeoulTech 4ra1n, pyn3rd and unam4