Apache Portable Runtime (APR) v1.6.01.6.3 SQL Injection via apr_dbd_oracle
CVE-2026-34191 Published on August 6, 2026

Apache Portable Runtime Utility: SQL Injection in apr_dbd_oracle
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Portable Runtime Utility via apr_dbd_oracle provider. This issue affects Apache Portable Runtime Utility: from 1.6.0 through 1.6.3

Vendor Advisory NVD

Timeline

reported

fixed in 1.6.x by r1936817 135 days later.

1.6.4 released

Weakness Type

What is a SQL Injection Vulnerability?

The software constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component.

CVE-2026-34191 has been classified to as a SQL Injection vulnerability or weakness.


Affected Versions

Apache Software Foundation Apache Portable Runtime Utility: