CVE-2026-32327: Apache Apr-Util

Critical severity, CVSS 9.1. EPSS: 0.5% chance of exploitation in the next 30 days.

A bug in APR-util version 1.6.3 (and earlier) allows a stack recursion attack against any library consumer which parses XML from untrusted sources and uses the apr_xml_quote_elem() function. Users are recommended to upgrade to version 1.6.4, which fixes this issue.

Affected products

  • Apache Apr-Util: before 1.6.4 (fixed in 1.6.4)

Published 2026-08-06. Last modified 2026-08-07.