THREATOPS
THREAT OPSThreat News › CVE-2026-32327: Apache Portable Runtime Utility: apr-util XML stack recursion crash

CVE-2026-32327: Apache Portable Runtime Utility: apr-util XML stack recursion crash

medoss_secPublished 2026-08-06

<p>Posted by Eric Covener on Aug 06</p>Severity: moderate <br /> <br /> Affected versions:<br /> <br /> - Apache Portable Runtime Utility (APR-util) through 1.6.3<br /> <br /> Description:<br /> <br /> A bug in APR-util version 1.6.3 (and earlier) allows a stack recursion attack against any library consumer which parses <br /> XML from untrusted sources and uses the apr_xml_quote_elem() function.<

Indicators of compromise

Original source: https://seclists.org/oss-sec/2026/q3/463