CVE-2026-34501: Apache Portable Runtime Utility: Heap buffer overflow in APR redis client
Heap-based Buffer Overflow vulnerability in Apache Portable Runtime Utility redis client.
This issue affects Apache Portable Runtime Utility: from 1.6.0 through 1.6.3.
Users are recommended to upgrade to version 1.6.4, which fixes the issue.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Apache Portable Runtime Utility (APR) redis clientto a version that resolves this vulnerability.Fixed in 1.6.4