← Vulnerability feed

Vulnerability record · CVE-2026-32327 · published 6 August 2026

CVE-2026-32327: Apache apr-util vulnerability

Apache · Apr Util

A bug in APR-util version 1.6.3 (and earlier) allows a stack recursion attack against any library consumer which parses XML from untrusted sources and uses the apr_xml_quote_elem() function. Users are recommended to upgrade to version 1.6.4, which fixes this issue.

9.1 CVSS 3.1 Critical EPSS 0.46% · top 62.8% CWE-674 · CWE-674
9.1CVSS 3.1 base score
0.46%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
7 Aug 2026Last modified by NVD

Description

A bug in APR-util version 1.6.3 (and earlier) allows a stack recursion attack against any library consumer which parses XML from untrusted sources and uses the apr_xml_quote_elem() function. Users are recommended to upgrade to version 1.6.4, which fixes this issue.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-32327 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2009-2412Apache apr-util vulnerabilityMultiple integer overflows in the Apache Portable Runtime (APR) library and the Apache Portable Utility library (aka APR-util) 0.9.x and 1.3.x allow …EPSS 14%9.1CVE-2026-34191Apache apr-util sql injection vulnerabilityImproper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Portable Runtime Utility via apr_dbd_ora…EPSS 0.59%7.5CVE-2026-34501Apache apr-util heap-based buffer overflow vulnerabilityHeap-based Buffer Overflow vulnerability in Apache Portable Runtime Utility redis client. This issue affects Apache Portable Runtime Utility: from 1.…EPSS 0.51%7.5CVE-2026-34502Apache apr-util heap-based buffer overflow vulnerabilityHeap-based Buffer Overflow vulnerability in Apache Portable Runtime Utility memcached client This issue affects Apache Portable Runtime Utility: from…EPSS 0.51%7.5CVE-2025-49506Apache apr-util vulnerabilityAPR-util versions 1.6.3 (and earlier) function apr_password_validate() was not constant-time with regards to hashes or passwords comparisons, potenti…EPSS 0.38%7.5CVE-2009-1955Apache APR-util expat XML parser nested entity denial of serviceThe expat XML parser in the apr_xml_* interface in Apache APR-util before 1.3.7 mishandles XML documents containing a large number of nested entity r…EPSS 53%analysed6.4CVE-2009-1956Apache apr-util vulnerabilityOff-by-one error in the apr_brigade_vprintf function in Apache APR-util before 1.3.5 on big-endian platforms allows remote attackers to obtain sensit…EPSS 12%5.0CVE-2010-1623Apache apr-util memory buffer overflow vulnerabilityMemory leak in the apr_brigade_split_line function in buckets/apr_brigade.c in the Apache Portable Runtime Utility library (aka APR-util) before 1.3.…EPSS 20%

Source: NIST National Vulnerability Database (record CVE-2026-32327), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.