Information Exposure Through Timing Discrepancy in Apache APR-util - CVE-2025-49506

 

Information Exposure Through Timing Discrepancy in Apache APR-util - CVE-2025-49506

Published: August 24, 2026


Vulnerability identifier: #VU144926
CSH Severity: Low
CVSS v4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-49506
CWE-ID: CWE-208
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to disclose sensitive information.

The vulnerability exists due to observable timing discrepancies in apr_password_validate() when comparing password hashes or passwords. A remote attacker can measure response times to infer sensitive information and disclose sensitive information.

The issue is particularly relevant on platforms without crypt() support, such as Windows, BeOS, NetWare, or Android.


Affected software

Apache APR-util
Debian Linux
openEuler
apr-util-pgsql
apr-util-odbc
apr-util-devel
apr-util-debugsource
apr-util-debuginfo
apr-util
apr-util (Debian package)

How to mitigate CVE-2025-49506

Install security update from vendor's website.

Apache APR-util - update to 1.6.4
apr-util-pgsql - addressed in versions 1.6.1-16, 1.6.4-1, 1.6.5-1
apr-util-odbc - addressed in versions 1.6.1-16, 1.6.4-1, 1.6.5-1
apr-util-devel - addressed in versions 1.6.1-16, 1.6.4-1, 1.6.5-1
apr-util-debugsource - addressed in versions 1.6.1-16, 1.6.4-1, 1.6.5-1
apr-util-debuginfo - addressed in versions 1.6.1-16, 1.6.4-1, 1.6.5-1
apr-util - addressed in versions 1.6.1-16, 1.6.4-1, 1.6.5-1
apr-util (Debian package) - update to 1.6.3-3+deb13u1

External References

Related Security Bulletins