Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-34032

Опубликовано: 04 мая 2026
Источник: redhat
CVSS3: 8.2

Описание

Improper Null Termination, Out-of-bounds Read vulnerability in Apache HTTP Server. This issue affects Apache HTTP Server: through 2.4.66. Users are recommended to upgrade to version 2.4.67, which fixes the issue.

A flaw was found in the mod_proxy_ajp module of httpd. When processing AJP (Apache JServ Protocol) messages, the server fails to properly check if a string is null-terminated before attempting to read it, allowing an attacker or a malformed request to cause a heap-based buffer over-read. This issue potentially leads to memory disclosure and a denial of service.

Отчет

To exploit this issue, the Apache HTTP Server must be configured to connect to an untrusted or compromised AJP backend server, limiting its exposure. Due to this reason, this flaw has been rated with a moderate severity. This flaw only affects configurations with mod_proxy_ajp loaded and being used. This module can be disabled via the configuration file if its functionality is not being used.

Меры по смягчению последствий

Disabling mod_proxy_ajp and restarting httpd will mitigate this flaw.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6httpdAffected
Red Hat Enterprise Linux 7httpdAffected
JBoss Core Services for RHEL 8jbcs-httpd24-httpdFixedRHSA-2026:2720022.06.2026
JBoss Core Services on RHEL 7jbcs-httpd24-httpdFixedRHSA-2026:2720022.06.2026
Red Hat Enterprise Linux 10httpdFixedRHSA-2026:2143327.05.2026
Red Hat Enterprise Linux 8httpdFixedRHSA-2026:2214001.06.2026
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update SupporthttpdFixedRHSA-2026:3684608.07.2026
Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-OnhttpdFixedRHSA-2026:3684608.07.2026
Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update SupporthttpdFixedRHSA-2026:3683108.07.2026
Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-OnhttpdFixedRHSA-2026:3683108.07.2026

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-170
https://bugzilla.redhat.com/show_bug.cgi?id=2464952httpd: mod_proxy_ajp: heap-based buffer over-read due to missing null-termination check

8.2 High

CVSS3

Связанные уязвимости

CVSS3: 5.3
ubuntu
3 месяца назад

Improper Null Termination, Out-of-bounds Read vulnerability in Apache HTTP Server. This issue affects Apache HTTP Server: through 2.4.66. Users are recommended to upgrade to version 2.4.67, which fixes the issue.

CVSS3: 5.3
nvd
3 месяца назад

Improper Null Termination, Out-of-bounds Read vulnerability in Apache HTTP Server. This issue affects Apache HTTP Server: through 2.4.66. Users are recommended to upgrade to version 2.4.67, which fixes the issue.

CVSS3: 5.3
msrc
3 месяца назад

Apache HTTP Server: mod_proxy_ajp: Heap Buffer Over-Read Due to Missing Null-Termination Check (ajp_msg_get_string)

CVSS3: 5.3
debian
3 месяца назад

Improper Null Termination, Out-of-bounds Read vulnerability in Apache ...

CVSS3: 5.3
github
3 месяца назад

Improper Null Termination, Out-of-bounds Read vulnerability in Apache HTTP Server. This issue affects Apache HTTP Server: through 2.4.66. Users are recommended to upgrade to version 2.4.67, which fixes the issue.

8.2 High

CVSS3