CVE Tracker

CVE-2026-32327 @ morris

Status
affects
Priority
9.1
Match score
4.0
Risk
Other Remote priv:user
CVSS
9.1 CRITICAL
Reason
cpe: apr-util; pkgs: apr-util, apr-util-devel; version: in-range: apr-util-1.5.2-6.el7_9.1
Created
2026-08-08T10:15:18Z
Updated
2026-08-22T10:16:17Z

Package interrogation (copy)

Run on the host — click to copy a command. RPM

PackageCommands
apr-util-1.5.2-6.el7_9.1
apr-util-devel

Inventory lookup

Search package inventory across systems, then return here. Create a ticket on systems the matcher missed.

Clear

Suggestions: apr-util · apr-util-devel

SystemMatchesTicket for CVE-2026-32327
morris ea-apr-util-devel 1.6.5 affects open

Same product CVEs in your queue

Other tickets that look like the same product (from match reason). Relate them here to triage this CVE as the primary.

CVECVSSKEVSystemsStatus MatchedAlready related
CVE-2025-49506 7.5 morris, mufasa not_applicable apr-util → CVE-2026-32327 linked here
CVE-2026-34502 7.5 morris, mufasa not_applicable apr-util → CVE-2026-32327 linked here
CVE-2026-34501 7.5 morris, mufasa not_applicable apr-util → CVE-2026-32327 linked here

Related CVE (same fix)

Point this ticket’s CVE at a higher-priority / same-fix primary so you only triage one.

Other CVEs related to this one as primary:

Related CVENoteTickets
CVE-2025-49506 same product as CVE-2026-32327 morris, mufasa
CVE-2026-34501 same product as CVE-2026-32327 morris, mufasa
CVE-2026-34502 same product as CVE-2026-32327 morris, mufasa

Host OS / kernel

OS
CloudLinux release 7.9 (Boris Yegorov) (7.9) · cloudlinux
Arch
x86_64
kernel_release
uname -r → 3.10.0-962.3.2.lve1.5.89.el7.x86_64
kernel_version
uname -v → #1 SMP Thu Jul 9 15:55:31 UTC 2026

For Linux kernel CVEs, kernel_version (Debian packaging / build string) often decides fixed vs not; kernel_release is used for upstream NVD range compares.

Same CVE on other hosts

Open the ticket for this CVE on another system.

System Status Priority Updated
mufasa affects 9.1 2026-08-22T10:16:17Z Open

Description

A bug in APR-util version 1.6.3 (and earlier) allows a stack recursion attack against any library consumer which parses XML from untrusted sources and uses the apr_xml_quote_elem() function.

Users are recommended to upgrade to version 1.6.4, which fixes this issue.

Determination

This CVE was published very recently (around 6–7 August 2026).
No TuxCare / CloudLinux ELS package containing the 1.6.4 fix appears to be available yet.
The main consumers on a cPanel/CloudLinux server are typically Apache (httpd) and any software that uses APR-util for XML parsing (including some EasyApache components).

Update status

Also apply to other systems with this CVE:

Add note only

Also add note on:

Mitigation log

2026-08-08T16:31:30Z — affects
This CVE was published very recently (around 6–7 August 2026). No TuxCare / CloudLinux ELS package containing the 1.6.4 fix appears to be available yet. The main consumers on a cPanel/CloudLinux server are typically Apache (httpd) and any software that uses APR-util for XML parsing (including some EasyApache components).
2026-08-08T16:32:24Z
Impact | Denial of service (crash) via malicious XML; potential for more severe impact depending on the consumer

References

NVD: CVE-2026-32327