CVE-2026-32327: Apache Portable Runtime Utility: apr-util XML stack recursion crash

Eric Covener <[email protected]>
Newsgroups gmane.comp.apache.apr.devel
Message-ID <[email protected]>
Severity: moderate 

Affected versions:

- Apache Portable Runtime Utility (APR-util) through 1.6.3

Description:

A bug in APR-util version 1.6.3 (and earlier) allows a stack recursion attack against any library consumer which parses XML from untrusted sources and uses the apr_xml_quote_elem() function.

Users are recommended to upgrade to version 1.6.4, which fixes this issue.

Credit:

Younghyo Cho @ CISLab, SeoulTech (finder)
4ra1n, pyn3rd and unam4 (finder)

References:

https://apr.apache.org/
https://www.cve.org/CVERecord?id=CVE-2026-32327

Timeline:

2026-03-07: Report received
2026-08-06: fixed in 1.6.x by r1936815
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.