CVE-2025-49506

CVE-2025-49506: Apache Portable Runtime Utility: apr_password_validate() vulnerable to timing attack

Vendor Apache Software Foundation
Product Apache Portable Runtime Utility
Weakness CWE-208
Published August 6, 2026
Last update August 6, 2026

CVSS base score

What the vulnerability does

01Description

APR-util versions 1.6.3 (and earlier) function apr_password_validate() was not constant-time with regards to hashes or passwords comparisons, potentially leaking their content via a side channel timing attack particularly on platforms without crypt() such as  Windows, BeOS, NetWare, or Android. Users are recommended to upgrade to version 1.6.4, which fixes this issue.

Key dates

02Disclosure timeline

August 6, 2026 CVE published
August 6, 2026 Record updated