CVE-2026-32327
A bug in APR-util version 1.6.3 (and earlier) allows a stack recursion attack against any library consumer which parses XML from untrusted sources and uses the aprxmlquote_elem() function.
Users are recommended to upgrade to version 1.6.4, which fixes this issue.
Package Versions Affected
Automatically patch vulnerabilities without upgrading
CVSS Version



Related Resources
References
http://www.openwall.com/lists/oss-security/2026/08/06/9, https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/32xxx/CVE-2026-32327.json, https://lists.apache.org/thread/hq27vj8yfno9tkwv0fpj6jksfzgxvth1, https://nvd.nist.gov/vuln/detail/CVE-2026-32327