CVE-2026-34032

medium
Published 2026-05-04 · Modified 2026-05-29
CVSS v3
5.3
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CVSS v4 NEW
—
not yet in upstream
VIR risk
5.3

Description

Important: httpd security update

Predictions

Exploit likelihood
63%
Patch ETA
—

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

Mitigation details

Source: Red Hat Errata — Red Hat Inc. · View original ↗ · Open-Errata-API

Description httpd: mod_proxy_ajp: heap-based buffer over-read due to missing null-termination check Red Hat statement To exploit this issue, the Apache HTTP Server must be configured to connect to an untrusted or compromised AJP backend server, limiting its exposure. Due to this reason, this flaw has been rated with a moderate severity. This flaw only affects configurations with mod_proxy_ajp…

Description

httpd: mod_proxy_ajp: heap-based buffer over-read due to missing null-termination check

Red Hat statement

To exploit this issue, the Apache HTTP Server must be configured to connect to an untrusted or compromised AJP backend server, limiting its exposure. Due to this reason, this flaw has been rated with a moderate severity. This flaw only affects configurations with mod_proxy_ajp loaded and being used. This module can be disabled via the configuration file if its functionality is not being used.

CVSS v3: 8.2 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H)

Errata / fixed releases

ProductPackageAdvisoryReleased
Red Hat Enterprise Linux 10httpd-0:2.4.63-13.el10_2.1RHSA-2026:214332026-05-27T00:00:00Z
Red Hat Enterprise Linux 9httpd-0:2.4.62-13.el9_8.1RHSA-2026:213912026-05-27T00:00:00Z
Red Hat Hardened Imageshttpd-main-2.4.67-0.1.hum1RHSA-2026:139382026-05-06T00:00:00Z

Package state

ProductPackageState
Red Hat Enterprise Linux 6httpdAffected
Red Hat Enterprise Linux 7httpdAffected
Red Hat Enterprise Linux 8httpd:2.4/httpdAffected
Red Hat JBoss Core Servicesmod_proxy_ajp.soAffected

Apply commands

bash fix
Apply RHSA-2026:21433 for Red Hat Enterprise Linux 10
yum update -y httpd
# or:
dnf upgrade -y httpd

Affected

VendorProductVersion
redhatRed Hat Enterprise Linux 6Affected
redhatRed Hat Enterprise Linux 7Affected
redhatRed Hat Enterprise Linux 8Affected
redhatRed Hat JBoss Core ServicesAffected

OS impact

OSVersionStatusFixed in
debian debianbookwormfixed2.4.67-1~deb12u2
debian debianbullseyefixed2.4.67-1~deb11u1
debian debianforkyfixed2.4.67-1
debian debiansidfixed2.4.67-1
debian debiantrixiefixed2.4.67-1~deb13u2
redhat rhel9fixed
suse slesaffected
almalinux almalinux9fixedhttpd-manual-2.4.62-13.el9_8.1.noarch.rpm
windows windowsaffected

Application impact

VendorProductVersionsFixed
apache apachehttp_server{"endExcluding":"2.4.67"}2.4.67

References

CWEs

CWE-125 CWE-170

Community-verified mitigations for this CVE will appear above when contributors publish them.

Verify integrity in audit chain (admin only). AS-IS.