It was discovered that APR-util incorrectly performed password hash comparisons in a way that was not constant-time. An attacker could possibly use this issue to obtain sensitive information. (CVE-2025-49506) It was discovered that APR-util incorrectly handled recursive XML element quoting.
USN-8719-1: APR-util vulnerabilities
calendar_today
September 3, 2026
domain
ubuntu