Critical severity9.1NVD Advisory· Published Aug 6, 2026· Updated Aug 7, 2026
CVE-2026-34191
CVE-2026-34191
Description
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Portable Runtime Utility via apr_dbd_oracle provider.
This issue affects Apache Portable Runtime Utility: from 1.6.0 through 1.6.3
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
4- Range: 1.6.0 - 1.6.3
- osv-coords2 versions
>= 1.6.0, < 1.6.5+ 1 more
- (no CPE)range: >= 1.6.0, < 1.6.5
- (no CPE)range: < 1.6.3-160000.3.1
Patches
Vulnerability mechanics
References
2- www.openwall.com/lists/oss-security/2026/08/06/10nvdMailing ListThird Party Advisory
- lists.apache.org/thread/8xch90zogywwpo5wnsf4o088mkxy4qtfnvdMailing ListVendor Advisory
News mentions
1- Apache Projects Hit by 25 Vulnerabilities: Fory, CXF, APR-util, Answer, Polaris AffectedVypr Intelligence · Aug 7, 2026