Known vulnerabilities in Apache APR-util

Software CPE: cpe:2.3:a:apache_foundation:apache_apr-util:*:*:*:*:*:*:*:*
Total vulnerabilities: 6
Public exploits: 0
Known exploited (KEV): 0
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting Apache APR-util Apache APR-util is affected by 6 known vulnerabilities: 2 high, 3 medium, 1 low Critical High Medium Low

Vulnerabilities (6)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU144930 - Heap-based Buffer Overflow
CVE-2026-34502
CWE-122 Medium
No
No
1.6.4 24.08.2026 SB20260824200
SB20260824221
SB20260824226
and 10 more
#VU144929 - Heap-based Buffer Overflow
CVE-2026-34501
CWE-122 High
No
No
1.6.4 24.08.2026 SB20260824200
SB20260824221
SB20260824226
and 9 more
#VU144928 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVE-2026-34191
CWE-89 Medium
No
No
1.6.4 24.08.2026 SB20260824200
SB20260824226
SB20260824227
and 6 more
#VU144927 - Uncontrolled Recursion
CVE-2026-32327
CWE-674 Medium
No
No
1.6.4 24.08.2026 SB20260824200
SB20260824221
SB20260824223
and 13 more
#VU144926 - Information Exposure Through Timing Discrepancy
CVE-2025-49506
CWE-208 Low
No
No
1.6.4 24.08.2026 SB20260824200
SB20260824221
SB20260824226
and 10 more
#VU71754 - Integer overflow
CVE-2022-25147
CWE-190 High
No
No
1.6.2 02.02.2023 SB2023020210
SB2023020212
SB2023020942
and 49 more