ITSECURITYWHAT HAPPENED · DOES IT AFFECT YOU · WHAT TO DO
BoardVulnerabilities › CVE-2026-28780
9.8Critical CVE-2026-28780 Apache

Heap-based Buffer Overflow vulnerability in mod_proxy_ajp of Apache HTTP Server.

Heap-based Buffer Overflow vulnerability in mod_proxy_ajp of Apache HTTP Server. If mod_proxy_ajp connects to a malicious AJP server this AJP server can send a malicious AJP message back to mod_proxy_ajp and cause it to write 4 attacker controlled bytes after the end of a heap based buffer. This issue affects Apache HTTP Server: through 2.4.66. Users are recommended to upgrade to version 2.4.67,

What happened

Heap-based Buffer Overflow vulnerability in mod_proxy_ajp of Apache HTTP Server. If mod_proxy_ajp connects to a malicious AJP server this AJP server can send a malicious AJP message back to mod_proxy_ajp and cause it to write 4 attacker controlled bytes after the end of a heap based buffer. This issue affects Apache HTTP Server: through 2.4.66. Users are recommended to upgrade to version 2.4.67, which fixes the issue.

Does it affect you

Not enough information

No products recorded, so this cannot be matched against anything.

What to do

  • Follow the vendor advisory for the fixed release and any interim mitigation.
    httpd.apache.org

Vendor's affected list

httpd
Everything below 2.4.67

Sources

A verdict here is derived from what you told us and what the vendor published. It is not an assessment of your environment. Why we never say you are safe.