CVE-2026-32327
Apache Portable Runtime Utility: apr-util XML stack recursion crash
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
A bug in APR-util version 1.6.3 (and earlier) allows a stack recursion attack against any library consumer which parses XML from untrusted sources and uses the apr_xml_quote_elem() function. Users are recommended to upgrade to version 1.6.4, which fixes this issue.
| CWE | CWE-674 |
| Vendor | apache software foundation |
| Product | apache portable runtime utility |
| Published | Aug 6, 2026 |
Stay Ahead of the Next One
Get instant alerts for apache software foundation apache portable runtime utility
Be the first to know when new unknown vulnerabilities affecting apache software foundation apache portable runtime utility are published — delivered to Slack, Telegram or Discord.
Get Free Alerts →
Free · No credit card · 60 sec setup
Affected Versions
Apache Software Foundation / Apache Portable Runtime Utility
0 ≤ 1.6.3
References
Credits
Younghyo Cho @ CISLab, SeoulTech 4ra1n, pyn3rd and unam4