CVE-2026-28780

critical
Published 2026-05-05 Β· Modified 2026-06-03
CVSS v3
9.8
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS v4 NEW
β€”
not yet in upstream
VIR risk
9.8

Description

Heap-based Buffer Overflow vulnerability in mod_proxy_ajp of Apache HTTP Server. If mod_proxy_ajp connects to a malicious AJP server this AJP server can send a malicious AJP message back to mod_proxy_ajp and cause it to write 4 attacker controlled bytes after the end of a heap based buffer. This issue affects Apache HTTP Server: through 2.4.66. Users are recommended to upgrade to version 2.4.67, which fixes the issue.

Predictions

Exploit likelihood
97%
Patch ETA
β€”

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

Mitigation details

Source: Red Hat Errata β€” Red Hat Inc. Β· View original β†— Β· Open-Errata-API

Description Apache HTTP Server: mod_proxy_ajp: Apache HTTP Server mod_proxy_ajp: Arbitrary code execution via heap-based buffer overflow CVSS v3: 8.1 (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H) Errata / fixed releases ProductPackageAdvisoryReleased Red Hat Enterprise Linux 10httpd-0:2.4.63-13.el10_2.1RHSA-2026:214332026-05-27T00:00:00Z Red Hat Enterprise Linux…

Description

Apache HTTP Server: mod_proxy_ajp: Apache HTTP Server mod_proxy_ajp: Arbitrary code execution via heap-based buffer overflow

CVSS v3: 8.1 (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H)

Errata / fixed releases

ProductPackageAdvisoryReleased
Red Hat Enterprise Linux 10httpd-0:2.4.63-13.el10_2.1RHSA-2026:214332026-05-27T00:00:00Z
Red Hat Enterprise Linux 9httpd-0:2.4.62-13.el9_8.1RHSA-2026:213912026-05-27T00:00:00Z

Package state

ProductPackageState
Red Hat Enterprise Linux 6httpdAffected
Red Hat Enterprise Linux 7httpdAffected
Red Hat Enterprise Linux 8httpd:2.4/httpdAffected
Red Hat JBoss Core ServiceshttpdAffected
Red Hat JBoss Core Servicesjbcs-httpd24-httpdAffected

Apply commands

bash fix
Apply RHSA-2026:21433 for Red Hat Enterprise Linux 10
yum update -y httpd
# or:
dnf upgrade -y httpd

Affected

VendorProductVersion
redhatRed Hat Enterprise Linux 6Affected
redhatRed Hat Enterprise Linux 7Affected
redhatRed Hat Enterprise Linux 8Affected
redhatRed Hat JBoss Core ServicesAffected
redhatRed Hat JBoss Core ServicesAffected

OS impact

suse SUSE Affected 1 release
VersionStatusFixed in
β€” Affected β€”
almalinux AlmaLinux Fixed 2 releases
VersionStatusFixed in
9 Fixed httpd-manual-2.4.62-13.el9_8.1.noarch.rpm
8 Fixed httpd-filesystem-2.4.37-65.module_el8.10.0+4185+0955a0d7.8.noarch.rpm
debian Debian Fixed 5 releases
VersionStatusFixed in
trixie Fixed 2.4.67-1~deb13u2
sid Fixed 2.4.67-1
forky Fixed 2.4.67-1
bullseye Fixed 2.4.67-1~deb11u1
bookworm Fixed 2.4.67-1~deb12u2
redhat Red Hat Fixed 2 releases
VersionStatusFixed in
9 Fixed β€”
8 Fixed β€”

Application impact

VendorProductVersionsFixed
apache apachehttp_server{"endExcluding":"2.4.67"}2.4.67

References

CWEs

CWE-122

Community-verified mitigations for this CVE will appear above when contributors publish them.

Verify integrity in audit chain (admin only). AS-IS.