CVE-2026-33857

medium
Published 2026-05-04 Β· Modified 2026-06-03
CVSS v3
5.3
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CVSS v4 NEW
β€”
not yet in upstream
VIR risk
5.3

Description

Out-of-bounds Read vulnerability in mod_proxy_ajp of Apache HTTP Server. This issue affects Apache HTTP Server: through 2.4.66. Users are recommended to upgrade to version 2.4.67, which fixes the issue.

Predictions

Exploit likelihood
63%
Patch ETA
β€”

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

Mitigation details

Source: Red Hat Errata β€” Red Hat Inc. Β· View original β†— Β· Open-Errata-API

Description httpd: mod_proxy_ajp: off-by-one out-of-bounds reads in AJP getter functions Red Hat statement To exploit this issue, the Apache HTTP Server must be configured to connect to an untrusted or compromised AJP backend server, limiting its exposure. Due to this reason, this flaw has been rated with a moderate severity. This flaw only affects configurations with mod_proxy_ajp loaded and…

Description

httpd: mod_proxy_ajp: off-by-one out-of-bounds reads in AJP getter functions

Red Hat statement

To exploit this issue, the Apache HTTP Server must be configured to connect to an untrusted or compromised AJP backend server, limiting its exposure. Due to this reason, this flaw has been rated with a moderate severity. This flaw only affects configurations with mod_proxy_ajp loaded and being used. This module can be disabled via the configuration file if its functionality is not being used.

CVSS v3: 7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)

Errata / fixed releases

ProductPackageAdvisoryReleased
Red Hat Enterprise Linux 10httpd-0:2.4.63-13.el10_2.1RHSA-2026:214332026-05-27T00:00:00Z
Red Hat Enterprise Linux 8httpd:2.4-8100020260519200905.489197e6RHSA-2026:221402026-06-01T00:00:00Z
Red Hat Enterprise Linux 9httpd-0:2.4.62-13.el9_8.1RHSA-2026:213912026-05-27T00:00:00Z

Package state

ProductPackageState
Red Hat Enterprise Linux 6httpdAffected
Red Hat Enterprise Linux 7httpdAffected
Red Hat Hardened ImageshttpdAffected
Red Hat JBoss Core Servicesmod_proxy_ajp.soAffected

Apply commands

bash fix
Apply RHSA-2026:21433 for Red Hat Enterprise Linux 10
yum update -y httpd
# or:
dnf upgrade -y httpd

Affected

VendorProductVersion
redhatRed Hat Enterprise Linux 6Affected
redhatRed Hat Enterprise Linux 7Affected
redhatRed Hat Hardened ImagesAffected
redhatRed Hat JBoss Core ServicesAffected

OS impact

suse SUSE Affected 1 release
VersionStatusFixed in
β€” Affected β€”
windows Windows Affected 1 release
VersionStatusFixed in
β€” Affected β€”
almalinux AlmaLinux Fixed 2 releases
VersionStatusFixed in
9 Fixed httpd-manual-2.4.62-13.el9_8.1.noarch.rpm
8 Fixed httpd-filesystem-2.4.37-65.module_el8.10.0+4185+0955a0d7.8.noarch.rpm
debian Debian Fixed 5 releases
VersionStatusFixed in
trixie Fixed 2.4.67-1~deb13u2
sid Fixed 2.4.67-1
forky Fixed 2.4.67-1
bullseye Fixed 2.4.67-1~deb11u1
bookworm Fixed 2.4.67-1~deb12u2
redhat Red Hat Fixed 2 releases
VersionStatusFixed in
9 Fixed β€”
8 Fixed β€”

Application impact

VendorProductVersionsFixed
apache apachehttp_server{"endExcluding":"2.4.67"}2.4.67

References

CWEs

CWE-125

Community-verified mitigations for this CVE will appear above when contributors publish them.

Verify integrity in audit chain (admin only). AS-IS.