CVE-2026-32327 @ mufasa
Status
affects
Priority
9.1
Match score
4.0
Risk
Other
Remote
priv:user
CVSS
9.1 CRITICAL
Reason
cpe: apr-util; pkgs: apr-util; version: in-range: apr-util-1.5.2-6.el7_9.1
Created
2026-08-08T10:15:18Z
Updated
2026-08-22T10:16:17Z
Package interrogation (copy)
Run on the host — click to copy a command. RPM
| Package | Commands |
|---|---|
| apr-util-1.5.2-6.el7_9.1 |
Inventory lookup
Search package inventory across systems, then return here. Create a ticket on systems the matcher missed.
Suggestions: apr-util
| System | Matches | Ticket for CVE-2026-32327 | |
|---|---|---|---|
| morris | apr-util 1.5.2; ea-apr-util 1.6.5; ea-apr-util-devel 1.6.5 | affects open | |
| mufasa | apr-util 1.5.2; ea-apr-util 1.6.5 | affects open |
Same product CVEs in your queue
Other tickets that look like the same product (from match reason). Relate them here to triage this CVE as the primary.
| CVE | CVSS | KEV | Systems | Status | Matched | Already related | |
|---|---|---|---|---|---|---|---|
| CVE-2025-49506 | 7.5 | morris, mufasa | not_applicable | apr-util | → CVE-2026-32327 | linked here | |
| CVE-2026-34502 | 7.5 | morris, mufasa | not_applicable | apr-util | → CVE-2026-32327 | linked here | |
| CVE-2026-34501 | 7.5 | morris, mufasa | not_applicable | apr-util | → CVE-2026-32327 | linked here |
Related CVE (same fix)
Point this ticket’s CVE at a higher-priority / same-fix primary so you only triage one.
Other CVEs related to this one as primary:
| Related CVE | Note | Tickets |
|---|---|---|
| CVE-2025-49506 | same product as CVE-2026-32327 | morris, mufasa |
| CVE-2026-34501 | same product as CVE-2026-32327 | morris, mufasa |
| CVE-2026-34502 | same product as CVE-2026-32327 | morris, mufasa |
Host OS / kernel
OS
CloudLinux release 7.9 (Boris Yegorov)
(7.9)
· cloudlinux
Arch
x86_64
kernel_release
uname -r → 3.10.0-962.3.2.lve1.5.89.el7.x86_64kernel_version
uname -v → #1 SMP Thu Jul 9 15:55:31 UTC 2026For Linux kernel CVEs, kernel_version (Debian packaging / build string) often decides fixed vs not; kernel_release is used for upstream NVD range compares.
Same CVE on other hosts
Open the ticket for this CVE on another system.
| System | Status | Priority | Updated | |
|---|---|---|---|---|
| morris | affects | 9.1 | 2026-08-22T10:16:17Z | Open |
Description
A bug in APR-util version 1.6.3 (and earlier) allows a stack recursion attack against any library consumer which parses XML from untrusted sources and uses the apr_xml_quote_elem() function. Users are recommended to upgrade to version 1.6.4, which fixes this issue.
Determination
This CVE was published very recently (around 6–7 August 2026). No TuxCare / CloudLinux ELS package containing the 1.6.4 fix appears to be available yet. The main consumers on a cPanel/CloudLinux server are typically Apache (httpd) and any software that uses APR-util for XML parsing (including some EasyApache components).
Update status
Add note only
Mitigation log
2026-08-08T16:31:30Z — affects
This CVE was published very recently (around 6–7 August 2026).
No TuxCare / CloudLinux ELS package containing the 1.6.4 fix appears to be available yet.
The main consumers on a cPanel/CloudLinux server are typically Apache (httpd) and any software that uses APR-util for XML parsing (including some EasyApache components).
2026-08-08T16:32:24Z
Impact | Denial of service (crash) via malicious XML; potential for more severe impact depending on the consumer
References
- https://lists.apache.org/thread/hq27vj8yfno9tkwv0fpj6jksfzgxvth1
- http://www.openwall.com/lists/oss-security/2026/08/06/9
NVD: CVE-2026-32327