Skip to content

APR-util versions 1.6.3

High7.5CVE-2025-49506 · Published Aug 6, 2026 · updated Sep 29, 2026

APR-util versions 1.6.3 (and earlier) function apr_password_validate() was not constant-time with regards to hashes or passwords comparisons, potentially leaking their content via a side channel timing attack particularly on platforms without crypt() such as  Windows, BeOS, NetWare, or Android. Users are recommended to upgrade to version 1.6.4, which fixes this issue.

Affected versions

PackageAffectedFixed in
Apache Portable Runtime Utility
Product
>= 1.2.0, <= 1.6.3No fix yet
Details and references

More Apache Software Foundation advisories

All Apache Software Foundation
Advisory
Apache Traffic Server: out-of-bounds write
High8.4Jul 29
Apache Traffic Server: server-side request forgery
High8.2Jul 29
Apache Traffic Server updates the HTTP/2 HPACK dynamic table before confirming...
Medium6.3Jul 29
Apache Traffic Server: stack buffer overflow
High8.2Jul 29
Apache Traffic Server: resource exhaustion
High8.2Jul 29
Apache Traffic Server: improper input validation
High8.2Jul 29

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.