THREATOPS
THREAT OPSThreat News › CVE-2025-49506: Apache Portable Runtime Utility: apr_password_validate() vulnerable to timing attack

CVE-2025-49506: Apache Portable Runtime Utility: apr_password_validate() vulnerable to timing attack

medoss_secPublished 2026-08-06

<p>Posted by Eric Covener on Aug 06</p>Severity: low <br /> <br /> Affected versions:<br /> <br /> - Apache Portable Runtime Utility (APR-util) 1.2.0 through 1.6.3<br /> <br /> Description:<br /> <br /> APR-util versions 1.6.3 (and earlier) function apr_password_validate() was not constant-time with regards to hashes or <br /> passwords comparisons, potentially leaking their content via a side cha

Indicators of compromise

Original source: https://seclists.org/oss-sec/2026/q3/462