Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
5049 articles · 189092 vulns · 37/41 feeds (7d)
← Back to list
9.1
CVE-2026-34191PATCHED
apache · apr-util

Apache Portable Runtime Utility: SQL Injection in apr_dbd_oracle

Description

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Portable Runtime Utility via apr_dbd_oracle provider. This issue affects Apache Portable Runtime Utility: from 1.6.0 through 1.6.3

Affected Products

VendorProductVersions
apacheapr-util1.6.0

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
apacheportable runtime (apr)cert_advisory90%

References

  • https://lists.apache.org/thread/8xch90zogywwpo5wnsf4o088mkxy4qtf(vendor-advisory)

Related News (4 articles)

Tier A
Microsoft MSRC3d ago
CVE-2026-34191 Apache Portable Runtime Utility: SQL Injection in apr_dbd_oracle
→ No new info (linked only)
Tier B
BSI Advisories5d ago
[NEU] [hoch] Apache Portable Runtime (APR): Mehrere Schwachstellen
→ No new info (linked only)
Tier C
oss-security6d ago
CVE-2026-34191: Apache Portable Runtime Utility: SQL Injection in apr_dbd_oracle
→ No new info (linked only)
Tier C
VulDB6d ago
CVE-2026-34191 | Apache Portable Runtime Utility up to 1.6.3 apr_dbd_oracle provider sql injection
→ No new info (linked only)
CVSS 3.19.1 CRITICAL
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
CISA KEV❌ No
Actively exploited❌ No
Patch available
https://lists.apache.org/thread/8xch90zogywwpo5wnsf4o088mkxy4qtf
CWECWE-89
PublishedAug 6, 2026
Trending Score43
Source articles4
Independent4
Info Completeness0/14
Missing: cve_id, title, description, vendor, product, versions, cvss, epss, cwe, kev, exploit, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

NONECVE-2026-49975EXP
Apache HTTP Server: mod_http2 denial of service
Trending: 86
MEDIUMCVE-2026-57914EXP
Apache Kerby: StackOverflow on parsing deeply nested ASN1 structures
Trending: 56
HIGHCVE-2026-57915
Apache Kerby: Kerberos Pre-Authentication Bypass
Trending: 51
HIGHCVE-2026-55969
Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift: integer overflow in TProtocol::checkReadBytesAvailable()
Trending: 42
HIGHCVE-2026-34502
Apache Portable Runtime Utility: Heap buffer overflow in APR memcached client
Trending: 37

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Aug 6, 2026
Discovered by ZDM
Aug 6, 2026
Patch Available
Aug 6, 2026