CVE Wiki Pixee · CVE intelligence
← All CVEs

CVE-2026-28780

Critical · CVSS 9.8

Apache HTTP Server mod_proxy_ajp — Heap-based Buffer Overflow (CWE-122, CWE-787)

CVSS
9.8
nvd
EPSS
1.38%
69th pct
KEV
No
Class
oss containerizable
CWE-122, CWE-787

Description

Heap-based Buffer Overflow vulnerability in mod_proxy_ajp of Apache HTTP Server. If mod_proxy_ajp connects to a malicious AJP server this AJP server can send a malicious AJP message back to mod_proxy_ajp and cause it to write 4 attacker controlled bytes after the end of a heap based buffer. This issue affects Apache HTTP Server: through 2.4.66. Users are recommended to upgrade to version 2.4.67, which fixes the issue.

Search profile — drives PoC discovery

Symbols mod_proxy_ajpAJPajp_msgproxy_ajpap_proxy_ajp_requestajp_read_headerajp_marshalap_proxy_ajp_canon
Keywords CVE-2026-28780Apache HTTP Servermod_proxy_ajpheap buffer overflowAJP malicious message2.4.662.4.67out-of-bounds writeheap overflow ajp
Versions: through 2.4.66

Affected packages

Bitnami apache 0 → 2.4.67

References

Status: enriched · ingested 2026-06-30T06:00:22.000Z · profiled 2026-07-01T06:30:14.000Z