Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-32327

Опубликовано: 06 авг. 2026
Источник: redhat
CVSS3: 6.2
EPSS Низкий

Описание

A bug in APR-util version 1.6.3 (and earlier) allows a stack recursion attack against any library consumer which parses XML from untrusted sources and uses the apr_xml_quote_elem() function. Users are recommended to upgrade to version 1.6.4, which fixes this issue.

A flaw was found in APR-util. A remote attacker could exploit a stack recursion vulnerability by providing specially crafted XML input to a library consumer that uses the apr_xml_quote_elem() function. This could lead to a denial of service (DoS) due to an application crash.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10apr-utilAffected
Red Hat Enterprise Linux 6apr-utilFix deferred
Red Hat Enterprise Linux 7apr-utilFix deferred
Red Hat Enterprise Linux 8apr-utilFix deferred
Red Hat Enterprise Linux 9apr-utilAffected
Red Hat Hardened Imagesapr-utilAffected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-776
https://bugzilla.redhat.com/show_bug.cgi?id=2512079apr-util: APR-util: Denial of Service via XML stack recursion attack

EPSS

Процентиль: 39%
0.00477
Низкий

6.2 Medium

CVSS3

Связанные уязвимости

CVSS3: 9.1
ubuntu
6 дней назад

A bug in APR-util version 1.6.3 (and earlier) allows a stack recursion attack against any library consumer which parses XML from untrusted sources and uses the apr_xml_quote_elem() function. Users are recommended to upgrade to version 1.6.4, which fixes this issue.

CVSS3: 9.1
nvd
6 дней назад

A bug in APR-util version 1.6.3 (and earlier) allows a stack recursion attack against any library consumer which parses XML from untrusted sources and uses the apr_xml_quote_elem() function. Users are recommended to upgrade to version 1.6.4, which fixes this issue.

msrc
6 дней назад

Apache Portable Runtime Utility: apr-util XML stack recursion crash

CVSS3: 9.1
debian
6 дней назад

A bug in APR-util version 1.6.3 (and earlier) allows a stack recursion ...

CVSS3: 9.1
github
6 дней назад

A bug in APR-util version 1.6.3 (and earlier) allows a stack recursion attack against any library consumer which parses XML from untrusted sources and uses the apr_xml_quote_elem() function. Users are recommended to upgrade to version 1.6.4, which fixes this issue.

EPSS

Процентиль: 39%
0.00477
Низкий

6.2 Medium

CVSS3