CVE-2026-28780
published 2026-05-05CVE-2026-28780: Heap-based Buffer Overflow vulnerability in mod_proxy_ajp of Apache HTTP Server. If mod_proxy_ajp connects to a malicious AJP server this AJP server can send a…
PriorityP261critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
1.38%
69.0th percentile
Heap-based Buffer Overflow vulnerability in mod_proxy_ajp of Apache HTTP Server.
If mod_proxy_ajp connects to a malicious AJP server this AJP server can send a malicious AJP message back to mod_proxy_ajp and cause it to write 4 attacker controlled bytes after the end of a heap based buffer.
This issue affects Apache HTTP Server: through 2.4.66.
Users are recommended to upgrade to version 2.4.67, which fixes the issue.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | http_server | < 2.4.67 | 2.4.67 |
| apache | httpd | — | — |
| apache_software_foundation | apache_http_server | <= 2.4.66 | — |
| httpd_2.4 | httpd | — | — |
| ubuntu | apache2 | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Vulnerability is in mod_proxy_ajp; detect Apache HTTP Server instances with mod_proxy_ajp enabled and proxying to backend AJP servers, as exploitation requires the server to connect to a malicious AJP backend ↗
- →Monitor for Apache HTTP Server versions 2.4.66 and below running mod_proxy_ajp as these are confirmed affected; flag any such version in inventory ↗
- →The overflow writes exactly 4 attacker-controlled bytes past the end of a heap buffer; heap corruption crash signatures or 4-byte out-of-bounds write patterns in Apache crash dumps may indicate exploitation attempts ↗
- ·Exploitation requires mod_proxy_ajp to be actively connecting to a backend AJP server; instances not using mod_proxy_ajp or not proxying to AJP backends are not affected ↗
- ·The attack vector is a malicious AJP backend server responding with a crafted message — the attacker must control or compromise the AJP backend (e.g., a rogue Tomcat instance) that Apache proxies to, not a direct client-side attack ↗
- ·Affected packages span multiple Red Hat product lines including RHEL 6–10 and Red Hat JBoss Core Services; patch coverage must be verified across all deployed variants ↗
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
vendor_redhat9.8CRITICAL
vendor_ubuntu8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-wpww-4qvv-xpv8: Heap-based Buffer Overflow vulnerability in mod_proxy_ajp of Apache HTTP Server
ghsa_unreviewed·2026-05-06
CVE-2026-28780 [CRITICAL] CWE-122 GHSA-wpww-4qvv-xpv8: Heap-based Buffer Overflow vulnerability in mod_proxy_ajp of Apache HTTP Server
Heap-based Buffer Overflow vulnerability in mod_proxy_ajp of Apache HTTP Server.
If mod_proxy_ajp connects to a malicious AJP server this AJP server can send a malicious AJP message back to mod_proxy_ajp and cause it to write 4 attacker controlled bytes after the end of a heap based buffer.
This issue affects Apache HTTP Server: through 2.4.66.
Users are recommended to upgrade to version 2.4.67, which fixes the issue.
VulDB
Apache HTTP Server up to 2.4.66 ajp_msg_check_header buffer overflow (EUVD-2026-27506)
vuldb·2026-05-05
CVE-2026-28780 [CRITICAL] Apache HTTP Server up to 2.4.66 ajp_msg_check_header buffer overflow (EUVD-2026-27506)
A vulnerability was found in Apache HTTP Server up to 2.4.66. It has been declared as critical. Impacted is the function ajp_msg_check_header. Executing a manipulation can lead to buffer overflow.
The identification of this vulnerability is CVE-2026-28780. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
Ubuntu
Apache HTTP Server vulnerabilities
vendor_ubuntu·2026-05-06·CVSS 8.8
CVE-2026-28780 [HIGH] Apache HTTP Server vulnerabilities
Title: Apache HTTP Server vulnerabilities
Summary: Several security issues were fixed in Apache HTTP Server.
Bartlomiej Dmitruk and Stanislaw Strzalkowski discovered that Apache
HTTP Server incorrectly handled certain memory operations when using the
HTTP/2 protocol. A remote attacker could use this issue to cause Apache
HTTP Server to crash, resulting in a denial of service, or possibly execute
arbitrary code. This issue only affected Ubuntu 26.04 LTS.
(CVE-2026-23918)
It was discovered that the Apache HTTP Server mod_rewrite module
incorrectly handled certain privileges. A local attacker could possibly use
this issue to obtain sensitive information. (CVE-2026-24072)
Andrew Lacambra, Elhanan Haenel, Tianshuo Han, and Tristan Madani
discovered that the Apache HTTP Server mod_proxy_ajp
Red Hat
Apache HTTP Server: mod_proxy_ajp: Apache HTTP Server mod_proxy_ajp: Arbitrary code execution via heap-based buffer overflow
vendor_redhat·2026-05-05·CVSS 9.8
CVE-2026-28780 [CRITICAL] CWE-787 Apache HTTP Server: mod_proxy_ajp: Apache HTTP Server mod_proxy_ajp: Arbitrary code execution via heap-based buffer overflow
Apache HTTP Server: mod_proxy_ajp: Apache HTTP Server mod_proxy_ajp: Arbitrary code execution via heap-based buffer overflow
A flaw was found in mod_proxy_ajp of Apache HTTP Server. This heap-based buffer overflow vulnerability allows a remote attacker, by connecting to a malicious AJP (Apache JServ Protocol) server, to send a specially crafted message. This message can cause mod_proxy_ajp to write attacker-controlled data beyond a heap-based buffer, potentially leading to arbitrary code execution or a denial of service.
Package: httpd (Red Hat Enterprise Linux 10) - Affected
Package: httpd (Red Hat Enterprise Linux 6) - Affected
Package: httpd (Red Hat Enterprise Linux 7) - Affected
Package: httpd:2.4/httpd (Red Hat Enterprise Linux 8) - Affected
Package: httpd (Red Hat Enterprise L
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-28780 httpd: Apache HTTP Server mod_proxy_ajp: Arbitrary code execution via heap-based buffer overflow [fedora-all]
bugzilla·2026-05-06·CVSS 9.8
CVE-2026-28780 [CRITICAL] CVE-2026-28780 httpd: Apache HTTP Server mod_proxy_ajp: Arbitrary code execution via heap-based buffer overflow [fedora-all]
CVE-2026-28780 httpd: Apache HTTP Server mod_proxy_ajp: Arbitrary code execution via heap-based buffer overflow [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Bugzilla
CVE-2026-28780 Apache HTTP Server: mod_proxy_ajp: Apache HTTP Server mod_proxy_ajp: Arbitrary code execution via heap-based buffer overflow
bugzilla·2026-05-05·CVSS 9.8
CVE-2026-28780 [CRITICAL] CVE-2026-28780 Apache HTTP Server: mod_proxy_ajp: Apache HTTP Server mod_proxy_ajp: Arbitrary code execution via heap-based buffer overflow
CVE-2026-28780 Apache HTTP Server: mod_proxy_ajp: Apache HTTP Server mod_proxy_ajp: Arbitrary code execution via heap-based buffer overflow
Heap-based Buffer Overflow vulnerability in mod_proxy_ajp of Apache HTTP Server.
If mod_proxy_ajp connects to a malicious AJP server this AJP server can send a malicious AJP message back to mod_proxy_ajp and cause it to write 4 attacker controlled bytes after the end of a heap based buffer.
This issue affects Apache HTTP Server: through 2.4.66.
Users are recommended to upgrade to version 2.4.67, which fixes the issue.
https://httpd.apache.org/security/vulnerabilities_24.htmlhttp://www.openwall.com/lists/oss-security/2026/05/05/9https://access.redhat.com/errata/RHSA-2026:21391https://access.redhat.com/errata/RHSA-2026:21433https://access.redhat.com/errata/RHSA-2026:22140https://access.redhat.com/errata/RHSA-2026:27200https://access.redhat.com/errata/RHSA-2026:27201https://access.redhat.com/errata/RHSA-2026:36373https://access.redhat.com/errata/RHSA-2026:36831https://access.redhat.com/errata/RHSA-2026:36846https://access.redhat.com/security/cve/CVE-2026-28780https://bugzilla.redhat.com/show_bug.cgi?id=2466913https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-28780.json
2026-05-05
Published