Critical severity9.1NVD Advisory· Published Aug 6, 2026· Updated Aug 7, 2026
CVE-2026-32327
CVE-2026-32327
Description
A bug in APR-util version 1.6.3 (and earlier) allows a stack recursion attack against any library consumer which parses XML from untrusted sources and uses the apr_xml_quote_elem() function.
Users are recommended to upgrade to version 1.6.4, which fixes this issue.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
14- osv-coords12 versionspkg:rpm/almalinux/apr-util-bdbpkg:rpm/almalinux/apr-util-opensslpkg:rpm/almalinux/apr-util-develpkg:rpm/almalinux/apr-util-mysqlpkg:rpm/almalinux/apr-util-ldappkg:rpm/almalinux/apr-util-odbcpkg:rpm/almalinux/apr-utilpkg:rpm/almalinux/apr-util-pgsqlpkg:rpm/almalinux/apr-util-lmdbpkg:bitnami/apr-utilpkg:rpm/almalinux/apr-util-sqlitepkg:rpm/opensuse/apr-util&distro=openSUSE%20Leap%2016.0
< 1.6.1-23.el9_8.1+ 11 more
- (no CPE)range: < 1.6.1-23.el9_8.1
- (no CPE)range: < 1.6.1-23.el9_8.1
- (no CPE)range: < 1.6.1-23.el9_8.1
- (no CPE)range: < 1.6.1-23.el9_8.1
- (no CPE)range: < 1.6.1-23.el9_8.1
- (no CPE)range: < 1.6.1-23.el9_8.1
- (no CPE)range: < 1.6.1-23.el9_8.1
- (no CPE)range: < 1.6.1-23.el9_8.1
- (no CPE)range: < 1.6.3-23.el10_2.1
- (no CPE)range: < 1.6.4
- (no CPE)range: < 1.6.1-23.el9_8.1
- (no CPE)range: < 1.6.3-160000.3.1
Patches
Vulnerability mechanics
References
2- www.openwall.com/lists/oss-security/2026/08/06/9nvdMailing ListThird Party Advisory
- lists.apache.org/thread/hq27vj8yfno9tkwv0fpj6jksfzgxvth1nvdMailing ListVendor Advisory
News mentions
1- Apache Projects Hit by 25 Vulnerabilities: Fory, CXF, APR-util, Answer, Polaris AffectedVypr Intelligence · Aug 7, 2026