CVE-2025-49506
HIGHApache Portable Runtime Utility: apr_password_validate() vulnerable to timing attack
Title source: cnaDescription
APR-util versions 1.6.3 (and earlier) function apr_password_validate() was not constant-time with regards to hashes or passwords comparisons, potentially leaking their content via a side channel timing attack particularly on platforms without crypt() such as Windows, BeOS, NetWare, or Android. Users are recommended to upgrade to version 1.6.4, which fixes this issue.
References (2)
Core 2
Core References
Vendor Advisory vendor-advisory
https://lists.apache.org/thread/2v8o3bj9pb7lfcr57bdnjg9xfkj04mg5
Scores
CVSS v3
7.5
EPSS
0.0039
EPSS Percentile
32.4%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
yes
Technical Impact
partial
Details
CWE
CWE-208
Status
published
Products (2)
apache/apr-util
1.2.0 - 1.6.4
Apache Software Foundation/Apache Portable Runtime Utility
1.2.0 - 1.6.3
Published
Aug 06, 2026
Tracked Since
Aug 06, 2026