---
id: CVE-2025-49506
title: >-
  APR-util versions 1.6.3 (and earlier) function apr_password_validate() was not
  constant-time with regards to hashes or passwords comparisons, potentially
  leaking their content via a side channel timing attack particularly on
  platforms wi…
summary: >-
  APR-util versions 1.6.3 (and earlier) function apr_password_validate() was not
  constant-time with regards to hashes or passwords comparisons, potentially
  leaking their content via a side channel timing attack particularly on
  platforms wi…
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'
cwe:
  - CWE-208
vendor: apache
product: apr-util
affected:
  - 'apr-util >= 1.2.0, < 1.6.4'
patched:
  - apr-util 1.6.4
published: '2026-08-06'
updated: '2026-09-29'
sourceUpdated: '2026-09-29T14:10:00.117'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-49506'
references:
  - url: 'https://lists.apache.org/thread/2v8o3bj9pb7lfcr57bdnjg9xfkj04mg5'
    label: security@apache.org
  - url: 'http://www.openwall.com/lists/oss-security/2026/08/06/8'
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
epss: 0.00379
epssPercentile: 0.29348
ingestedAt: '2026-09-29T14:36:14.079Z'
---

## Overview

APR-util versions 1.6.3 (and earlier) function apr_password_validate() was not constant-time with regards to hashes or passwords comparisons, potentially leaking their content via a side channel timing attack particularly on platforms without crypt() such as  Windows, BeOS, NetWare, or Android.

Users are recommended to upgrade to version 1.6.4, which fixes this issue.

## Affected

- `apr-util >= 1.2.0, < 1.6.4`

## Remediation

Upgrade past the affected range:

- `apr-util 1.6.4`
