CVE-2026-34032

medium
Published 2026-05-04 ยท Modified 2026-06-03
CVSS v3
5.3
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CVSS v4 NEW
โ€”
not yet in upstream
VIR risk
5.3

Description

Improper Null Termination, Out-of-bounds Read vulnerability in Apache HTTP Server. This issue affects Apache HTTP Server: through 2.4.66. Users are recommended to upgrade to version 2.4.67, which fixes the issue.

Predictions

Exploit likelihood
63%
Patch ETA
โ€”

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

Mitigation details

Source: Red Hat Errata โ€” Red Hat Inc. ยท View original โ†— ยท Open-Errata-API

Description httpd: mod_proxy_ajp: heap-based buffer over-read due to missing null-termination check Red Hat statement To exploit this issue, the Apache HTTP Server must be configured to connect to an untrusted or compromised AJP backend server, limiting its exposure. Due to this reason, this flaw has been rated with a moderate severity. This flaw only affects configurations with mod_proxy_ajpโ€ฆ

Description

httpd: mod_proxy_ajp: heap-based buffer over-read due to missing null-termination check

Red Hat statement

To exploit this issue, the Apache HTTP Server must be configured to connect to an untrusted or compromised AJP backend server, limiting its exposure. Due to this reason, this flaw has been rated with a moderate severity. This flaw only affects configurations with mod_proxy_ajp loaded and being used. This module can be disabled via the configuration file if its functionality is not being used.

CVSS v3: 8.2 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H)

Errata / fixed releases

ProductPackageAdvisoryReleased
Red Hat Enterprise Linux 10httpd-0:2.4.63-13.el10_2.1RHSA-2026:214332026-05-27T00:00:00Z
Red Hat Enterprise Linux 9httpd-0:2.4.62-13.el9_8.1RHSA-2026:213912026-05-27T00:00:00Z
Red Hat Hardened Imageshttpd-main-2.4.67-0.1.hum1RHSA-2026:139382026-05-06T00:00:00Z

Package state

ProductPackageState
Red Hat Enterprise Linux 6httpdAffected
Red Hat Enterprise Linux 7httpdAffected
Red Hat Enterprise Linux 8httpd:2.4/httpdAffected
Red Hat JBoss Core Servicesmod_proxy_ajp.soAffected

Apply commands

bash fix
Apply RHSA-2026:21433 for Red Hat Enterprise Linux 10
yum update -y httpd
# or:
dnf upgrade -y httpd

Affected

VendorProductVersion
redhatRed Hat Enterprise Linux 6Affected
redhatRed Hat Enterprise Linux 7Affected
redhatRed Hat Enterprise Linux 8Affected
redhatRed Hat JBoss Core ServicesAffected

OS impact

suse SUSE Affected 1 release
VersionStatusFixed in
โ€” Affected โ€”
windows Windows Affected 1 release
VersionStatusFixed in
โ€” Affected โ€”
almalinux AlmaLinux Fixed 2 releases
VersionStatusFixed in
9 Fixed httpd-manual-2.4.62-13.el9_8.1.noarch.rpm
8 Fixed httpd-filesystem-2.4.37-65.module_el8.10.0+4185+0955a0d7.8.noarch.rpm
debian Debian Fixed 5 releases
VersionStatusFixed in
trixie Fixed 2.4.67-1~deb13u2
sid Fixed 2.4.67-1
forky Fixed 2.4.67-1
bullseye Fixed 2.4.67-1~deb11u1
bookworm Fixed 2.4.67-1~deb12u2
redhat Red Hat Fixed 2 releases
VersionStatusFixed in
9 Fixed โ€”
8 Fixed โ€”

Application impact

VendorProductVersionsFixed
apache apachehttp_server{"endExcluding":"2.4.67"}2.4.67

References

CWEs

CWE-125 CWE-170

Community-verified mitigations for this CVE will appear above when contributors publish them.

Verify integrity in audit chain (admin only). AS-IS.