It was discovered that APR-util incorrectly performed password hash comparisons in a way that was not constant-time. An attacker could possibly use this issue to obtain sensitive information. (CVE-2025-49506) It was discovered that APR-util incorrectly handled recursive XML element quoting. An attacker could possibly use this issue to cause applications using APR-util to crash, resulting in a denial of service. (CVE-2026-32327) It was discovered that the APR-util Redis client incorrectly handled certain network data, resulting in a heap-based buffer overflow. A remote attacker could possibly use this issue to cause APR-util applications to crash or execute arbitrary code. This issue only affected Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, Ubuntu 24.04 LTS, and Ubuntu 26.04 LTS. (CVE-2026-34501) It was discovered that the APR-util memcached client incorrectly handled certain network data, resulting in a heap-based buffer overflow. A remote attacker could possibly use this issue to cause APR-util applications to crash or execute arbitrary code. (CVE-2026-34502)
A critical vulnerability (CVE-2026-32327, CVSS 9.1) in Apache APR-util's XML handling can cause a denial of service via recursive element quoting, affecting versions prior to 1.6.4. Two high-severity heap buffer overflows (CVE-2026-34501 & CVE-2026-34502, CVSS 7.5) in the Redis and memcached clients allow remote code execution or crashes, with CVE-2026-34501 affecting versions 1.6.0 through 1.6.3. A separate high-severity timing side-channel vulnerability (CVE-2025-49506, CVSS 7.5) in password comparisons affects versions 1.2.0 through 1.6.3; all issues are fixed in APR-util version 1.6.4.