Back

HIGH

Apache Portable Runtime Utility: Heap buffer overflow in APR redis client

Published Aug 6, 2026

Description

Heap-based Buffer Overflow vulnerability in Apache Portable Runtime Utility redis client.

This issue affects Apache Portable Runtime Utility: from 1.6.0 through 1.6.3.

Users are recommended to upgrade to version 1.6.4, which fixes the issue.

Affected products

Remediation

Red Hat statement

The impact of this vulnerability is rated as Moderate. Although the flaw involves a heap buffer overflow and the CVSS base score reflects an unauthenticated network vector, exploitation requires the attacker to control or compromise the Redis server that the application queries. An attacker cannot trigger this condition by sending data directly to the affected application — they must first be in a position to influence Redis responses, either by compromising the Redis backend or performing a man-in-the-middle attack on the connection. Additionally, the overflow does not result in arbitrary code execution; the observed impact is limited to a denial of service. This prerequisite significantly limits real-world exploitability.

Red Hat mitigation

Ensure that the Redis server used by the application is deployed in a trusted, network-segregated environment and is not accessible to untrusted parties. Where possible, configure authentication and TLS on the Redis connection to reduce the risk of a compromised or spoofed Redis server.

References (7)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner apache
Published Aug 6, 2026
Updated Aug 6, 2026
Reserved Mar 30, 2026
CISA Vulnrichment
Updated Aug 6, 2026
NVD
Status Analyzed
Modified Aug 7, 2026
Red Hat
Severity Moderate
Public date Aug 6, 2026
ENISA EUVD
Assigner apache
Published Aug 6, 2026
Updated Aug 6, 2026
Exploited since n/a
EUVD-2026-53917