High severity7.5NVD Advisory· Published Aug 6, 2026· Updated Aug 7, 2026
CVE-2025-49506
CVE-2025-49506
Description
APR-util versions 1.6.3 (and earlier) function apr_password_validate() was not constant-time with regards to hashes or passwords comparisons, potentially leaking their content via a side channel timing attack particularly on platforms without crypt() such as Windows, BeOS, NetWare, or Android.
Users are recommended to upgrade to version 1.6.4, which fixes this issue.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
14- osv-coords12 versionspkg:rpm/almalinux/apr-util-develpkg:rpm/almalinux/apr-util-sqlitepkg:rpm/almalinux/apr-util-ldappkg:rpm/almalinux/apr-util-bdbpkg:rpm/almalinux/apr-util-odbcpkg:rpm/almalinux/apr-util-lmdbpkg:rpm/almalinux/apr-utilpkg:rpm/almalinux/apr-util-mysqlpkg:rpm/opensuse/apr-util&distro=openSUSE%20Leap%2016.0pkg:rpm/almalinux/apr-util-opensslpkg:bitnami/apr-utilpkg:rpm/almalinux/apr-util-pgsql
< 1.6.1-23.el9_8.1+ 11 more
- (no CPE)range: < 1.6.1-23.el9_8.1
- (no CPE)range: < 1.6.1-23.el9_8.1
- (no CPE)range: < 1.6.1-23.el9_8.1
- (no CPE)range: < 1.6.1-23.el9_8.1
- (no CPE)range: < 1.6.1-23.el9_8.1
- (no CPE)range: < 1.6.3-23.el10_2.1
- (no CPE)range: < 1.6.1-23.el9_8.1
- (no CPE)range: < 1.6.1-23.el9_8.1
- (no CPE)range: < 1.6.3-160000.3.1
- (no CPE)range: < 1.6.1-23.el9_8.1
- (no CPE)range: >= 1.2.0, < 1.6.4
- (no CPE)range: < 1.6.1-23.el9_8.1
Patches
Vulnerability mechanics
References
2- www.openwall.com/lists/oss-security/2026/08/06/8nvdMailing ListThird Party Advisory
- lists.apache.org/thread/2v8o3bj9pb7lfcr57bdnjg9xfkj04mg5nvdMailing ListVendor Advisory
News mentions
1- Apache Projects Hit by 25 Vulnerabilities: Fory, CXF, APR-util, Answer, Polaris AffectedVypr Intelligence · Aug 7, 2026