Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
5005 articles · 188942 vulns · 37/41 feeds (7d)
← Back to list
7.5
CVE-2025-49506PATCHED
apache · apr-util

Apache Portable Runtime Utility: apr_password_validate() vulnerable to timing attack

Description

APR-util versions 1.6.3 (and earlier) function apr_password_validate() was not constant-time with regards to hashes or passwords comparisons, potentially leaking their content via a side channel timing attack particularly on platforms without crypt() such as  Windows, BeOS, NetWare, or Android. Users are recommended to upgrade to version 1.6.4, which fixes this issue.

Affected Products

VendorProductVersions
apacheapr-util1.2.0

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
apacheportable runtime (apr)cert_advisory90%

References

  • https://lists.apache.org/thread/2v8o3bj9pb7lfcr57bdnjg9xfkj04mg5(vendor-advisory)

Related News (4 articles)

Tier A
Microsoft MSRC3d ago
CVE-2025-49506 Apache Portable Runtime Utility: apr_password_validate() vulnerable to timing attack
→ No new info (linked only)
Tier B
BSI Advisories5d ago
[NEU] [hoch] Apache Portable Runtime (APR): Mehrere Schwachstellen
→ No new info (linked only)
Tier C
oss-security5d ago
CVE-2025-49506: Apache Portable Runtime Utility: apr_password_validate() vulnerable to timing attack
→ No new info (linked only)
Tier C
VulDB6d ago
CVE-2025-49506 | Apache Portable Runtime Utility up to 1.6.3 apr_password_validate comparison
→ No new info (linked only)
CVSS 3.17.5 HIGH
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CISA KEV❌ No
Actively exploited❌ No
Patch available
https://lists.apache.org/thread/2v8o3bj9pb7lfcr57bdnjg9xfkj04mg5
CWECWE-208
PublishedAug 6, 2026
Trending Score37
Source articles4
Independent4
Info Completeness0/14
Missing: cve_id, title, description, vendor, product, versions, cvss, epss, cwe, kev, exploit, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

NONECVE-2026-49975EXP
Apache HTTP Server: mod_http2 denial of service
Trending: 87
MEDIUMCVE-2026-57914EXP
Apache Kerby: StackOverflow on parsing deeply nested ASN1 structures
Trending: 56
HIGHCVE-2026-57915
Apache Kerby: Kerberos Pre-Authentication Bypass
Trending: 51
CRITICALCVE-2026-34191
Apache Portable Runtime Utility: SQL Injection in apr_dbd_oracle
Trending: 43
HIGHCVE-2026-55969
Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift: integer overflow in TProtocol::checkReadBytesAvailable()
Trending: 42

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Aug 6, 2026
Discovered by ZDM
Aug 6, 2026
Patch Available
Aug 6, 2026