Apache Portable Runtime (APR) v1.6.01.6.3 SQL Injection via apr_dbd_oracle
CVE-2026-34191 Published on August 6, 2026
Apache Portable Runtime Utility: SQL Injection in apr_dbd_oracle
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Portable Runtime Utility via apr_dbd_oracle provider.
This issue affects Apache Portable Runtime Utility: from 1.6.0 through 1.6.3
Timeline
reported
fixed in 1.6.x by r1936817 135 days later.
1.6.4 released
Weakness Type
What is a SQL Injection Vulnerability?
The software constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component.
CVE-2026-34191 has been classified to as a SQL Injection vulnerability or weakness.
Affected Versions
Apache Software Foundation Apache Portable Runtime Utility:- Version 1.6.0, <= 1.6.3 is affected.