PT-2026-73243 · Bitnami · Apr-Util

Published

2026-08-17

·

Updated

2026-08-17

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
A bug in APR-util version 1.6.3 (and earlier) allows a stack recursion attack against any library consumer which parses XML from untrusted sources and uses the apr xml quote elem() function.
Users are recommended to upgrade to version 1.6.4, which fixes this issue.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

BIT-APR-UTIL-2026-32327

Affected Products

Apr-Util