{"id":"CVE-2025-49506","title":"APR-util versions 1.6.3 (and earlier) function apr_password_validate() was not constant-time with regards to hashes or passwords comparisons, potentially leaking their content via a side channel timing attack particularly on platforms wi…","summary":"APR-util versions 1.6.3 (and earlier) function apr_password_validate() was not constant-time with regards to hashes or passwords comparisons, potentially leaking their content via a side channel timing attack particularly on platforms wi…","severity":"high","cvss":7.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","cwe":["CWE-208"],"vendor":"apache","product":"apr-util","affected":["apr-util >= 1.2.0, < 1.6.4"],"patched":["apr-util 1.6.4"],"published":"2026-08-06","updated":"2026-09-29","sourceUpdated":"2026-09-29T14:10:00.117","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2025-49506","references":[{"url":"https://lists.apache.org/thread/2v8o3bj9pb7lfcr57bdnjg9xfkj04mg5","label":"security@apache.org"},{"url":"http://www.openwall.com/lists/oss-security/2026/08/06/8","label":"af854a3a-2127-422b-91ae-364da2661108"}],"tags":["nvd"],"epss":0.00379,"epssPercentile":0.29348,"ingestedAt":"2026-09-29T14:36:14.079Z","slug":"CVE-2025-49506","body":"## Overview\n\nAPR-util versions 1.6.3 (and earlier) function apr_password_validate() was not constant-time with regards to hashes or passwords comparisons, potentially leaking their content via a side channel timing attack particularly on platforms without crypt() such as  Windows, BeOS, NetWare, or Android.\n\nUsers are recommended to upgrade to version 1.6.4, which fixes this issue.\n\n## Affected\n\n- `apr-util >= 1.2.0, < 1.6.4`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `apr-util 1.6.4`","depth":"twilight","depthScore":41,"depthScoreParts":{"impact":41.3,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}