PT-2026-38461 · Bitnami · Apache

Published

2026-05-07

·

Updated

2026-05-07

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Heap-based Buffer Overflow vulnerability in mod proxy ajp of Apache HTTP Server. If mod proxy ajp connects to a malicious AJP server this AJP server can send a malicious AJP message back to mod proxy ajp and cause it to write 4 attacker controlled bytes after the end of a heap based buffer.
This issue affects Apache HTTP Server: through 2.4.66.
Users are recommended to upgrade to version 2.4.67, which fixes the issue.

Related Identifiers

BIT-APACHE-2026-28780

Affected Products

Apache