PT-2026-37040 · Apache · Apache Http Server

Andrew Lacambra

+3

·

Published

2026-05-05

·

Updated

2026-05-05

·

CVE-2026-28780

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Name of the Vulnerable Software and Affected Versions Apache HTTP Server versions prior to 2.4.67
Description A heap-based buffer overflow exists in the mod proxy ajp module. This occurs when mod proxy ajp connects to a malicious AJP server, which can send a specially crafted AJP message causing the server to write four attacker-controlled bytes beyond the end of a heap-based buffer.
Recommendations Upgrade to version 2.4.67.

Heap Based Buffer Overflow

Weakness Enumeration

Related Identifiers

CVE-2026-28780

Affected Products

Apache Http Server