Heap BO in Apache APR-util redis client (1.6.0-1.6.3, Fixed 1.6.4)
CVE-2026-34501 Published on August 6, 2026
Apache Portable Runtime Utility: Heap buffer overflow in APR redis client
Heap-based Buffer Overflow vulnerability in Apache Portable Runtime Utility redis client.
This issue affects Apache Portable Runtime Utility: from 1.6.0 through 1.6.3.
Users are recommended to upgrade to version 1.6.4, which fixes the issue.
Timeline
reported
fixed in 1.6.x by r1936810 132 days later.
Weakness Type
Heap-based Buffer Overflow
A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory, generally meaning that the buffer was allocated using a routine such as malloc().
Affected Versions
Apache Software Foundation Apache Portable Runtime Utility:- Version 1.6.0, <= 1.6.3 is affected.