Apache Portable Runtime Utility是美国Apache基金会开源的一个提供跨平台运行时接口的组件工具集。 Apache Portable Runtime Utility 1.6.3及之前版本存在侧信道信息泄露漏洞,该漏洞源于apr_password_validate()函数在哈希或密码比较时未采用常数时间算法,容易受到侧信道时序攻击,可能导致哈希或密码内容泄露。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Apache Software Foundation | Apache Portable Runtime Utility | 1.2.0≤ 1.6.3 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Apache Software Foundation | Apache Portable Runtime Utility | 1.2.0 ~ 1.6.3 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-64640 | 5.3 MEDIUM | Apache Polaris: register endpoint reads attacker-controlled storage location before allowe |
| CVE-2026-68079 | Apache CXF: DefaultEncryptingCodeDataProvider allows unlimited authorization code replay | |
| CVE-2026-54225 | Apache CXF: Denial of Service attack via large attachments | |
| CVE-2026-57819 | Apache CXF: No default restriction on the amount of form parameters per message | |
| CVE-2026-64958 | Apache CXF: Denial of service via message header attachments | |
| CVE-2026-66909 | Apache CXF: Unsafe deserialization of inbound JMS ObjectMessage | |
| CVE-2026-57817 | Apache CXF: The authorization code hash (c_hash) is not enforced for the hybrid OIDC flow | |
| CVE-2026-65432 | Apache CXF: XXE via WSDL/XSD import parsing | |
| CVE-2026-68481 | Apache CXF: Revocation bypass in DefaultEncryptingOAuthDataProvider | |
| CVE-2026-32327 | Apache Portable Runtime Utility: apr-util XML stack recursion crash | |
| CVE-2026-65583 | Apache CXF: Self-issued ID token claims validation skipped | |
| CVE-2026-63687 | Apache CXF: JwtRequestCodeFilter silently overrides outer PKCE and nonce parameters | |
| CVE-2026-61466 | Apache CXF: OAuth2 Dynamic Client Registration Scope Self-Escalation | |
| CVE-2026-57818 | Apache CXF: OAuth2 Authorization Code Replay via TOCTOU in JCacheCodeDataProvider | |
| CVE-2026-34502 | Apache Portable Runtime Utility: Heap buffer overflow in APR memcached client | |
| CVE-2026-34501 | Apache Portable Runtime Utility: Heap buffer overflow in APR redis client | |
| CVE-2026-34191 | Apache Portable Runtime Utility: SQL Injection in apr_dbd_oracle |
No comments yet