THREAT OPS › Threat News › CVE-2025-49506: Apache Portable Runtime Utility: apr_password_validate() vulnerable to timing attack
CVE-2025-49506: Apache Portable Runtime Utility: apr_password_validate() vulnerable to timing attack
<p>Posted by Eric Covener on Aug 06</p>Severity: low <br /> <br /> Affected versions:<br /> <br /> - Apache Portable Runtime Utility (APR-util) 1.2.0 through 1.6.3<br /> <br /> Description:<br /> <br /> APR-util versions 1.6.3 (and earlier) function apr_password_validate() was not constant-time with regards to hashes or <br /> passwords comparisons, potentially leaking their content via a side cha
Indicators of compromise
- CVE-2025-49506cve
Original source: https://seclists.org/oss-sec/2026/q3/462