Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
5071 articles · 189145 vulns · 37/41 feeds (7d)
← Back to list
7.5
CVE-2026-34502PATCHED
apache · apr-util

Apache Portable Runtime Utility: Heap buffer overflow in APR memcached client

Description

Heap-based Buffer Overflow vulnerability in Apache Portable Runtime Utility memcached client This issue affects Apache Portable Runtime Utility: from 1.3.0 through 1.6.3.

Affected Products

VendorProductVersions
apacheapr-util1.3.0

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
apacheportable runtime (apr)cert_advisory90%

References

  • https://lists.apache.org/thread/spk5643m4vq0mb8h5b9hz9gkp57ombl8(vendor-advisory)

Related News (4 articles)

Tier A
Microsoft MSRC3d ago
CVE-2026-34502 Apache Portable Runtime Utility: Heap buffer overflow in APR memcached client
→ No new info (linked only)
Tier B
BSI Advisories5d ago
[NEU] [hoch] Apache Portable Runtime (APR): Mehrere Schwachstellen
→ No new info (linked only)
Tier C
oss-security6d ago
CVE-2026-34502: Apache Portable Runtime Utility: Heap buffer overflow in APR memcached client
→ No new info (linked only)
Tier C
VulDB6d ago
CVE-2026-34502 | Apache Portable Runtime Utility up to 1.6.3 buffer overflow
→ No new info (linked only)
CVSS 3.17.5 HIGH
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CISA KEV❌ No
Actively exploited❌ No
Patch available
https://lists.apache.org/thread/spk5643m4vq0mb8h5b9hz9gkp57ombl8
CWECWE-122
PublishedAug 6, 2026
Trending Score36
Source articles4
Independent4
Info Completeness0/14
Missing: cve_id, title, description, vendor, product, versions, cvss, epss, cwe, kev, exploit, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

NONECVE-2026-49975EXP
Apache HTTP Server: mod_http2 denial of service
Trending: 84
MEDIUMCVE-2026-57914EXP
Apache Kerby: StackOverflow on parsing deeply nested ASN1 structures
Trending: 55
HIGHCVE-2026-57915
Apache Kerby: Kerberos Pre-Authentication Bypass
Trending: 50
CRITICALCVE-2026-34191
Apache Portable Runtime Utility: SQL Injection in apr_dbd_oracle
Trending: 42
HIGHCVE-2026-55969
Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift: integer overflow in TProtocol::checkReadBytesAvailable()
Trending: 41

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Aug 6, 2026
Discovered by ZDM
Aug 6, 2026
Patch Available
Aug 6, 2026