CVE-2026-28780

Heap-based Buffer Overflow vulnerability in mod_proxy_ajp of Apache HTTP Server. If mod_proxy_ajp connects to a malicious AJP server this AJP server can send a malicious AJP message back to mod_proxy_ajp and cause it to write 4 attacker controlled bytes after the end of a heap based buffer. This issue affects Apache HTTP Server: through 2.4.66. Users are recommended to upgrade to version 2.4.67, which fixes the issue.
Configurations

Configuration 1 (hide)

cpe:2.3:a:apache:http_server:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-05-05 22:16

Updated : 2026-09-14 13:17


NVD link : CVE-2026-28780

Mitre link : CVE-2026-28780

CVE.ORG link : CVE-2026-28780


JSON object : View

Products Affected

apache

  • http_server
CWE
CWE-122

Heap-based Buffer Overflow

CWE-787

Out-of-bounds Write