CVE-2026-34191
EUVD-2026-5391806.08.2026, 15:16
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Portable Runtime Utility via apr_dbd_oracle provider.
This issue affects Apache Portable Runtime Utility: from 1.6.0 through 1.6.3Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| apache | apr-util | 1.6.0 ≤ 𝑥 ≤ 1.6.3 |
𝑥
= Vulnerable software versions
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| apache | portable_runtime_utility | 1.6.0 ≤ 𝑥 ≤ 1.6.3 | CNA |
Debian Releases
Ubuntu Releases
openSUSE / SLES Releases
openSUSE Product | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| apr-util-devel |
| ||||||||||||||||||||||||
| libapr-util1 |
| ||||||||||||||||||||||||
| libapr-util1-dbd-mysql |
| ||||||||||||||||||||||||
| libapr-util1-dbd-pgsql |
| ||||||||||||||||||||||||
| libapr-util1-dbd-sqlite3 |
| ||||||||||||||||||||||||
| libapr-util1-devel |
|