Understanding and Defending Against CVE-2026-32327: A Stack Recursion Attack in APR-util
CVE-2026-32327 is a critical vulnerability in APR-util version 1.6.3 and earlier, allowing a stack recursion attack when parsing XML from untrusted sources using the apr_xml_quote_elem() function. This vulnerability has a CVSS score of 9.1 and can lead to high confidentiality and availability impacts. Users are recommended to upgrade to version 1.6.4 to fix this issue.