CVE-2026-32327: Apache Portable Runtime Utility: apr-util XML stack recursion crash
A bug in APR-util version 1.6.3 (and earlier) allows a stack recursion attack against any library consumer which parses XML from untrusted sources and uses the aprxmlquoteelem() function.
Users are recommended to upgrade to version 1.6.4, which fixes this issue.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Apache Portable Runtime Utility: apr-utilto a version that resolves this vulnerability.Fixed in 1.6.4