CVE-2026-32327: CWE-674 Uncontrolled Recursion in Apache Software Foundation Apache Portable Runtime Utility
A bug in APR-util version 1.6.3 (and earlier) allows a stack recursion attack against any library consumer which parses XML from untrusted sources and uses the apr_xml_quote_elem() function. Users are recommended to upgrade to version 1.6.4, which fixes this issue.
AI Analysis
Technical Summary
CVE-2026-32327 describes a bug in APR-util versions 1.6.3 and earlier where the apr_xml_quote_elem() function is susceptible to a stack recursion attack when processing XML from untrusted sources. This vulnerability arises from improper handling of XML elements leading to excessive recursion on the stack, potentially causing application instability or denial of service. The issue is fixed in APR-util version 1.6.4.
Potential Impact
The vulnerability can cause a stack recursion attack resulting in denial of service or application crashes for any software using the affected APR-util versions to parse XML from untrusted sources with apr_xml_quote_elem(). No known exploits are reported in the wild at this time.
Mitigation Recommendations
Users should upgrade to APR-util version 1.6.4, which contains the fix for this vulnerability. No other mitigations are indicated or necessary once the upgrade is applied.
CVE-2026-32327: CWE-674 Uncontrolled Recursion in Apache Software Foundation Apache Portable Runtime Utility
Description
A bug in APR-util version 1.6.3 (and earlier) allows a stack recursion attack against any library consumer which parses XML from untrusted sources and uses the apr_xml_quote_elem() function. Users are recommended to upgrade to version 1.6.4, which fixes this issue.
Affected software
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-32327 describes a bug in APR-util versions 1.6.3 and earlier where the apr_xml_quote_elem() function is susceptible to a stack recursion attack when processing XML from untrusted sources. This vulnerability arises from improper handling of XML elements leading to excessive recursion on the stack, potentially causing application instability or denial of service. The issue is fixed in APR-util version 1.6.4.
Potential Impact
The vulnerability can cause a stack recursion attack resulting in denial of service or application crashes for any software using the affected APR-util versions to parse XML from untrusted sources with apr_xml_quote_elem(). No known exploits are reported in the wild at this time.
Mitigation Recommendations
Users should upgrade to APR-util version 1.6.4, which contains the fix for this vulnerability. No other mitigations are indicated or necessary once the upgrade is applied.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-qfxp-vc85-jg39
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-32327"]
- Ecosystems
- []
- Database Specific Severity
- null
- Cvss Version
- null
Threat ID: 6a74cf74bf8831d5391ac5b6
Added to database: 08/06/2026, 18:16:20 UTC
Last enriched: 08/06/2026, 18:23:08 UTC
Last updated: 08/07/2026, 03:40:59 UTC
Views: 3
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.