CVE-2026-32327: Apache Apr-Util
Critical severity, CVSS 9.1. EPSS: 0.5% chance of exploitation in the next 30 days.
A bug in APR-util version 1.6.3 (and earlier) allows a stack recursion attack against any library consumer which parses XML from untrusted sources and uses the apr_xml_quote_elem() function. Users are recommended to upgrade to version 1.6.4, which fixes this issue.
Affected products
- Apache Apr-Util: before 1.6.4 (fixed in 1.6.4)
Published 2026-08-06. Last modified 2026-08-07.