Apache · Apache Http Server · CVE-2026-34032
**Name of the Vulnerable Software and Affected Versions**
Apache HTTP Server versions prior to 2.4.67
**Description**
An improper null termination leads to an out-of-bounds read in the `mod proxy ajp` module. Specifically, the `ajp msg get string()` function fails to perform a null-termination check, which may allow a remote attacker to cause a denial of service.
**Recommendations**
Upgrade to version 2.4.67.