Apache Software FoundationCVE-2025-49506
APR-util versions 1.6.3
High7.5CVE-2025-49506 · Published Aug 6, 2026 · updated Sep 29, 2026
APR-util versions 1.6.3 (and earlier) function apr_password_validate() was not constant-time with regards to hashes or passwords comparisons, potentially leaking their content via a side channel timing attack particularly on platforms without crypt() such as Windows, BeOS, NetWare, or Android. Users are recommended to upgrade to version 1.6.4, which fixes this issue.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| Apache Portable Runtime Utility Product | >= 1.2.0, <= 1.6.3 | No fix yet |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- Severity from
- CISA (its enrichment of the CVE record)
- Weakness
- CWE-208
More Apache Software Foundation advisories
All Apache Software Foundation| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Jul 29 | Apache Traffic Server: out-of-bounds write | High8.4 | No fix yet |
| Jul 29 | Apache Traffic Server: server-side request forgery | High8.2 | No fix yet |
| Jul 29 | Apache Traffic Server updates the HTTP/2 HPACK dynamic table before confirming... | Medium6.3 | No fix yet |
| Jul 29 | Apache Traffic Server: stack buffer overflow | High8.2 | No fix yet |
| Jul 29 | Apache Traffic Server: resource exhaustion | High8.2 | No fix yet |
| Jul 29 | Apache Traffic Server: improper input validation | High8.2 | No fix yet |