PT-2026-68498 · Apache+2 · Apr-Util+2

CVE-2025-49506

·

Published

2026-08-06

·

Updated

2026-09-10

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions APR-util versions prior to 1.6.4
Description The function apr password validate() does not operate in constant-time when comparing hashes or passwords. This behavior can lead to the leakage of sensitive content through a side channel timing attack, which occurs when an attacker analyzes the time taken to execute a cryptographic operation to deduce information. This issue is especially prominent on platforms that lack the crypt() function, including Windows, BeOS, NetWare, and Android.
Recommendations Upgrade to version 1.6.4.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2026:66341
ALSA-2026:66392
AZL-94628
BIT-APR-UTIL-2025-49506
CVE-2025-49506
ECHO-601D-E0EE-C283
OESA-2026-3325
OESA-2026-3326
OESA-2026-3327
OESA-2026-3328
OESA-2026-3409
OPENSUSE-SU-2026:21672-1
RHSA-2026:58474
SUSE-SU-2026:3905-1
SUSE-SU-2026:3937-1
SUSE-SU-2026:3938-1
USN-8719-1

Affected Products

Apr-Util
Linuxmint
Ubuntu