CVE-2026-28780

Heap-based Buffer Overflow vulnerability in mod_proxy_ajp of Apache HTTP Server. If mod_proxy_ajp connects to a malicious AJP server this AJP server can send a malicious AJP message back to mod_proxy_ajp and cause it to write 4 attacker controlled bytes after the end of a heap based buffer. This issue affects Apache HTTP Server: through 2.4.66. Users are recommended to upgrade to version 2.4.67, which fixes the issue.
Configurations

Configuration 1 (hide)

cpe:2.3:a:apache:http_server:*:*:*:*:*:*:*:*

History

28 Jul 2026, 13:17

Type Values Removed Values Added
References
  • () https://access.redhat.com/errata/RHSA-2026:47046 -

25 Jul 2026, 11:10

Type Values Removed Values Added
Summary
  • (es) Vulnerabilidad de desbordamiento de búfer basado en montículo en mod_proxy_ajp del Servidor HTTP Apache. Si mod_proxy_ajp se conecta a un servidor AJP malicioso, este servidor AJP puede enviar un mensaje AJP malicioso de vuelta a mod_proxy_ajp y hacer que escriba 4 bytes controlados por el atacante después del final de un búfer basado en montículo. Este problema afecta al Servidor HTTP Apache: hasta 2.4.66. Se recomienda a los usuarios actualizar a la versión 2.4.67, que corrige el problema.

09 Jul 2026, 13:16

Type Values Removed Values Added
References
  • () https://access.redhat.com/errata/RHSA-2026:36831 -
  • () https://access.redhat.com/errata/RHSA-2026:36846 -

08 Jul 2026, 13:16

Type Values Removed Values Added
References
  • () https://access.redhat.com/errata/RHSA-2026:36373 -

30 Jun 2026, 03:18

Type Values Removed Values Added
CWE CWE-787
References
  • () https://access.redhat.com/errata/RHSA-2026:21391 -
  • () https://access.redhat.com/errata/RHSA-2026:21433 -
  • () https://access.redhat.com/errata/RHSA-2026:22140 -
  • () https://access.redhat.com/errata/RHSA-2026:27200 -
  • () https://access.redhat.com/errata/RHSA-2026:27201 -
  • () https://access.redhat.com/security/cve/CVE-2026-28780 -
  • () https://bugzilla.redhat.com/show_bug.cgi?id=2466913 -
  • () https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-28780.json -

06 May 2026, 20:31

Type Values Removed Values Added
CPE cpe:2.3:a:apache:http_server:*:*:*:*:*:*:*:*
References () https://httpd.apache.org/security/vulnerabilities_24.html - () https://httpd.apache.org/security/vulnerabilities_24.html - Release Notes, Vendor Advisory
References () http://www.openwall.com/lists/oss-security/2026/05/05/9 - () http://www.openwall.com/lists/oss-security/2026/05/05/9 - Mailing List, Third Party Advisory
First Time Apache http Server
Apache

06 May 2026, 16:16

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8

05 May 2026, 23:16

Type Values Removed Values Added
References
  • () http://www.openwall.com/lists/oss-security/2026/05/05/9 -

05 May 2026, 22:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-05-05 22:16

Updated : 2026-07-28 13:17


NVD link : CVE-2026-28780

Mitre link : CVE-2026-28780

CVE.ORG link : CVE-2026-28780


JSON object : View

Products Affected

apache

  • http_server
CWE
CWE-122

Heap-based Buffer Overflow

CWE-787

Out-of-bounds Write