CVE-2012-0840: Apache Portable Runtime

Medium severity, CVSS 5.0. EPSS: 42.1% chance of exploitation in the next 30 days.

tables/apr_hash.c in the Apache Portable Runtime (APR) library through 1.4.5 computes hash values without restricting the ability to trigger hash collisions predictably, which allows context-dependent attackers to cause a denial of service (CPU consumption) via crafted input to an application that maintains a hash table.

Affected products

  • Apache Portable Runtime: up to and including 1.4.5; version 0.9.1 only; version 0.9.2 only; version 0.9.2-dev only; version 0.9.3 only; version 0.9.3-dev only; …

Published 2012-02-10. Last modified 2026-06-16.