Apr-util
11 CVEs tracked. None of them is in CISA KEV.
This hub aggregates every CVE we track for Apr-util, a product in the oss libraries space. Use it to gauge the current risk picture and drill into individual advisories.
Apr-util CVEs per month
| Month | CVEs |
|---|---|
| 2024-10 | 0 |
| 2024-11 | 0 |
| 2024-12 | 0 |
| 2025-01 | 0 |
| 2025-02 | 0 |
| 2025-03 | 0 |
| 2025-04 | 0 |
| 2025-05 | 0 |
| 2025-06 | 0 |
| 2025-07 | 0 |
| 2025-08 | 0 |
| 2025-09 | 0 |
| 2025-10 | 0 |
| 2025-11 | 0 |
| 2025-12 | 0 |
| 2026-01 | 0 |
| 2026-02 | 0 |
| 2026-03 | 0 |
| 2026-04 | 0 |
| 2026-05 | 0 |
| 2026-06 | 0 |
| 2026-07 | 0 |
| 2026-08 | 5 |
| 2026-09 | 0 |
Severity
How the 11 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.
- Critical3
- High4
- Medium4
Latest CVEs
The 11 most recently published vulnerabilities affecting Apr-util.
- CVE-2025-49506Apache Portable Runtime Utility: apr_password_validate() vulnerable to timing attack7.5
- CVE-2026-32327Apache Portable Runtime Utility: apr-util XML stack recursion crash9.1
- CVE-2026-34191Apache Portable Runtime Utility: SQL Injection in apr_dbd_oracle9.1
- CVE-2026-34501Apache Portable Runtime Utility: Heap buffer overflow in APR redis client7.5
- CVE-2026-34502Apache Portable Runtime Utility: Heap buffer overflow in APR memcached client7.5
- CVE-2011-1928The fnmatch implementation in apr_fnmatch.c in the Apache Portable Runtime (APR) library 1.4.3 and 1.4.4, and the Apache HTTP Server 2.2.18, allows remote attackers to cause a denial of service (in...4.3
- CVE-2010-1623Memory leak in the apr_brigade_split_line function in buckets/apr_brigade.c in the Apache Portable Runtime Utility library (aka APR-util) before 1.3.10, as used in the mod_reqtimeout module in the ...5.0
- CVE-2009-2412Multiple integer overflows in the Apache Portable Runtime (APR) library and the Apache Portable Utility library (aka APR-util) 0.9.x and 1.3.x allow remote attackers to cause a denial of service (a...10.0
- CVE-2009-1956Off-by-one error in the apr_brigade_vprintf function in Apache APR-util before 1.3.5 on big-endian platforms allows remote attackers to obtain sensitive information or cause a denial of service (ap...6.4
- CVE-2009-1955The expat XML parser in the apr_xml_* interface in xml/apr_xml.c in Apache APR-util before 1.3.7, as used in the mod_dav and mod_dav_svn modules in the Apache HTTP Server, allows remote attackers t...7.5
- CVE-2009-0023The apr_strmatch_precompile function in strmatch/apr_strmatch.c in Apache APR-util before 1.3.5 allows remote attackers to cause a denial of service (daemon crash) via crafted input involving (1) a...4.3
Product grouping is registry-driven, with AI assist and human review. How it works