High severity7.5NVD Advisory· Published Aug 6, 2026· Updated Aug 7, 2026
CVE-2026-34501
CVE-2026-34501
Description
Heap-based Buffer Overflow vulnerability in Apache Portable Runtime Utility redis client.
This issue affects Apache Portable Runtime Utility: from 1.6.0 through 1.6.3.
Users are recommended to upgrade to version 1.6.4, which fixes the issue.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
14- Range: 1.6.0 - 1.6.3
- osv-coords12 versionspkg:rpm/almalinux/apr-util-mysqlpkg:rpm/almalinux/apr-util-odbcpkg:rpm/almalinux/apr-util-sqlitepkg:rpm/almalinux/apr-util-bdbpkg:bitnami/apr-utilpkg:rpm/opensuse/apr-util&distro=openSUSE%20Leap%2016.0pkg:rpm/almalinux/apr-util-pgsqlpkg:rpm/almalinux/apr-util-develpkg:rpm/almalinux/apr-utilpkg:rpm/almalinux/apr-util-ldappkg:rpm/almalinux/apr-util-lmdbpkg:rpm/almalinux/apr-util-openssl
< 1.6.1-23.el9_8.1+ 11 more
- (no CPE)range: < 1.6.1-23.el9_8.1
- (no CPE)range: < 1.6.1-23.el9_8.1
- (no CPE)range: < 1.6.1-23.el9_8.1
- (no CPE)range: < 1.6.1-23.el9_8.1
- (no CPE)range: >= 1.6.0, < 1.6.4
- (no CPE)range: < 1.6.3-160000.3.1
- (no CPE)range: < 1.6.1-23.el9_8.1
- (no CPE)range: < 1.6.1-23.el9_8.1
- (no CPE)range: < 1.6.1-23.el9_8.1
- (no CPE)range: < 1.6.1-23.el9_8.1
- (no CPE)range: < 1.6.3-23.el10_2.1
- (no CPE)range: < 1.6.1-23.el9_8.1
Patches
Vulnerability mechanics
References
2- www.openwall.com/lists/oss-security/2026/08/06/11nvdMailing ListThird Party Advisory
- lists.apache.org/thread/o8h6c7cq86fplxlnry6c3rn9x0ovq8mvnvdMailing ListVendor Advisory
News mentions
1- Apache Projects Hit by 25 Vulnerabilities: Fory, CXF, APR-util, Answer, Polaris AffectedVypr Intelligence · Aug 7, 2026