Information Exposure Through Timing Discrepancy in Apache APR-util - CVE-2025-49506
Published: August 24, 2026
Vulnerability details
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to observable timing discrepancies in apr_password_validate() when comparing password hashes or passwords. A remote attacker can measure response times to infer sensitive information and disclose sensitive information.
The issue is particularly relevant on platforms without crypt() support, such as Windows, BeOS, NetWare, or Android.
Affected software
Debian Linux
openEuler
apr-util-pgsql
apr-util-odbc
apr-util-devel
apr-util-debugsource
apr-util-debuginfo
apr-util
apr-util (Debian package)
How to mitigate CVE-2025-49506
apr-util-pgsql - addressed in versions 1.6.1-16, 1.6.4-1, 1.6.5-1
apr-util-odbc - addressed in versions 1.6.1-16, 1.6.4-1, 1.6.5-1
apr-util-devel - addressed in versions 1.6.1-16, 1.6.4-1, 1.6.5-1
apr-util-debugsource - addressed in versions 1.6.1-16, 1.6.4-1, 1.6.5-1
apr-util-debuginfo - addressed in versions 1.6.1-16, 1.6.4-1, 1.6.5-1
apr-util - addressed in versions 1.6.1-16, 1.6.4-1, 1.6.5-1
apr-util (Debian package) - update to 1.6.3-3+deb13u1