CVE-2026-34502

Source
https://cve.org/CVERecord?id=CVE-2026-34502
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-34502.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-34502
Aliases
Downstream
ALPINE (1)
AZL (1)
BELL (1)
DEBIAN (1)
ECHO (1)
MGASA (1)
OESA (5)
openSUSE (1)
RHSA (4)
RLSA (3)
ROOT (3)
SUSE (4)
UBUNTU (1)
Related
Published
2026-08-06T14:31:07Z
Modified
2026-09-29T18:26:47Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
Apache Portable Runtime Utility: Heap buffer overflow in APR memcached client
Details

Heap-based Buffer Overflow vulnerability in Apache Portable Runtime Utility memcached client

This issue affects Apache Portable Runtime Utility: from 1.3.0 through 1.6.3.

Database specific
{
    "cna_assigner":  "apache",
    "cwe_ids":  [
        "CWE-122"
    ],
    "osv_generated_from":  "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/34xxx/CVE-2026-34502.json",
    "unresolved_ranges":  [
        {
            "extracted_events":  [
                {
                    "introduced":  "1.3.0"
                },
                {
                    "last_affected":  "1.6.3"
                }
            ],
            "source":  "AFFECTED_FIELD"
        },
        {
            "extracted_events":  [
                {
                    "introduced":  "1.3.0"
                },
                {
                    "fixed":  "1.6.3"
                }
            ],
            "source":  "DESCRIPTION"
        }
    ]
}
References

Affected packages

Git / github.com/apache/apr-util

Affected ranges

Type
GIT
Repo
https://github.com/apache/apr-util
Events
Database specific
Show details
{
    "cpe":  "cpe:2.3:a:apache:apr-util:*:*:*:*:*:*:*:*",
    "extracted_events":  [
        {
            "introduced":  "1.3.0"
        },
        {
            "last_affected":  "1.6.3"
        }
    ],
    "source":  "CPE_RANGE"
}

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-34502.json"