CVE-2026-34502
CVE-2026-34502: 2 tracked advisory records across Apache, Red Hat. Compare vendor sources and published fix guidance.
Compare the source-linked records below. Ratings and product/version details belong to each advisory; they are not a single CVE-wide score or proof that every listed product is affected. How VulniPulse collects and checks evidence.
Vendor advisory comparison
Apache
1 advisory- Advisory severityHigh7.5
High [CVE-2026-34502] Heap-based Buffer Overflow vulnerability in Apache Portable Runtime Utility memcached client This issue affects Apache Portable Runtime Utility: from 1.3.0 through 1.6.3
CVE-2026-34502Source published Source updated
Heap-based Buffer Overflow vulnerability in Apache Portable Runtime Utility memcached client This issue affects Apache Portable Runtime Utility: from 1.3.0 through 1.6.3.
- Affected products in this advisory
- Apache Portable Runtime
- Source-reported affected versions
- 1.3.0 through 1.6.3.
- through 1.6.3
- Source-reported fixed versions
- No fixed-version detail extracted. This does not mean no fix exists.
- Mitigation guidance
- No mitigation guidance extracted; consult the source.
Red Hat
1 advisory- Advisory severityHigh7.5
High [CVE-2026-34502] Heap buffer overflow in APR memcached client
CVE-2026-34502Source published Source updated
Heap-based Buffer Overflow vulnerability in Apache Portable Runtime Utility memcached client This issue affects Apache Portable Runtime Utility: from 1.3.0 through 1.6.3. A remote, unauthenticated attacker can cause the application to crash or become unresponsive by sending a specially crafted response from a malicious or compromised memcached server, resulting in a denial of service. The impact of this vulnerability is rated as Moderate. While the flaw is network-reachable and requires no authentication against the application itself, exploitation depends on the attacker controlling or compromising the memcached server that the application queries. An attacker cannot trigger the denial of service by sending data directly to the affected application — they must first be in a position to…
- Affected products in this advisory
- Red Hat Enterprise Linux 10
- Red Hat Enterprise Linux 9
- Red Hat Hardened Images
- Red Hat Enterprise Linux 6
3 more entries in the full advisory.
- Source-reported affected versions
- 1.3.0
- 1.6.3
- Source-reported fixed versions
- apr-util-0:1.6.3-23.el10_2.1
- apr-util-0:1.6.1-23.el9_8.1
- apr-util-main-1.6.5-1.hum1
- RHSA-2026:66392
2 more entries in the full advisory.
- Mitigation guidance
- Restrict network access for applications that use the `apr-util` memcached client to communicate only with trusted memcached servers. Ensure that Red Hat products are configured to avoid connecting to untrusted or publicly exposed memcached instances. If the memcached client functionality is not essential, consider disabling or removing any dependent components. A service restart may be required for changes to take effect.
Android app · Google Play
Turn CVE research into alerts on your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.