Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-33857

Опубликовано: 04 мая 2026
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

Out-of-bounds Read vulnerability in mod_proxy_ajp of Apache HTTP Server. This issue affects Apache HTTP Server: through 2.4.66. Users are recommended to upgrade to version 2.4.67, which fixes the issue.

A flaw was found in the mod_proxy_ajp module of httpd. When processing AJP (Apache JServ Protocol) messages, the AJP getter functions attempt to read data beyond the allocated buffer size, allowing an attacker or a malformed request to cause an out-of-bounds read. This issue leads to a denial of service.

Отчет

To exploit this issue, the Apache HTTP Server must be configured to connect to an untrusted or compromised AJP backend server, limiting its exposure. Due to this reason, this flaw has been rated with a moderate severity. This flaw only affects configurations with mod_proxy_ajp loaded and being used. This module can be disabled via the configuration file if its functionality is not being used.

Меры по смягчению последствий

Disabling mod_proxy_ajp and restarting httpd will mitigate this flaw.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6httpdAffected
Red Hat Enterprise Linux 7httpdAffected
JBoss Core Services for RHEL 8jbcs-httpd24-httpdFixedRHSA-2026:2720022.06.2026
JBoss Core Services on RHEL 7jbcs-httpd24-httpdFixedRHSA-2026:2720022.06.2026
Red Hat Enterprise Linux 10httpdFixedRHSA-2026:2143327.05.2026
Red Hat Enterprise Linux 10.0 Extended Update SupporthttpdFixedRHSA-2026:4704628.07.2026
Red Hat Enterprise Linux 8httpdFixedRHSA-2026:2214001.06.2026
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update SupporthttpdFixedRHSA-2026:3684608.07.2026
Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-OnhttpdFixedRHSA-2026:3684608.07.2026
Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update SupporthttpdFixedRHSA-2026:3683108.07.2026

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-125
https://bugzilla.redhat.com/show_bug.cgi?id=2464953httpd: mod_proxy_ajp: off-by-one out-of-bounds reads in AJP getter functions

EPSS

Процентиль: 32%
0.00393
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 5.3
ubuntu
3 месяца назад

Out-of-bounds Read vulnerability in mod_proxy_ajp of Apache HTTP Server. This issue affects Apache HTTP Server: through 2.4.66. Users are recommended to upgrade to version 2.4.67, which fixes the issue.

CVSS3: 5.3
nvd
3 месяца назад

Out-of-bounds Read vulnerability in mod_proxy_ajp of Apache HTTP Server. This issue affects Apache HTTP Server: through 2.4.66. Users are recommended to upgrade to version 2.4.67, which fixes the issue.

CVSS3: 5.3
msrc
3 месяца назад

Apache HTTP Server: Off-by-one OOB reads in AJP getter functions

CVSS3: 5.3
debian
3 месяца назад

Out-of-bounds Read vulnerability in mod_proxy_ajp of Apache HTTP Ser ...

CVSS3: 5.3
github
3 месяца назад

Out-of-bounds Read vulnerability in mod_proxy_ajp of Apache HTTP Server. This issue affects Apache HTTP Server: through 2.4.66. Users are recommended to upgrade to version 2.4.67, which fixes the issue.

EPSS

Процентиль: 32%
0.00393
Низкий

7.5 High

CVSS3