Executive brief
The Apache HTTP Server is a widely used web server for hosting websites and applications. A vulnerability in its AJP proxy module allows a malicious backend server to send specially crafted messages that corrupt the web server's memory. This could allow an attacker to take full control of the server, potentially leading to data theft or service disruption.
Technical details
A heap-based buffer overflow exists in the mod_proxy_ajp module of Apache HTTP Server within the ajp_msg_check_header() function. When the server is configured to proxy requests to a backend using the Apache JServ Protocol (AJP), a compromised or malicious backend server can return a crafted AJP message. This message triggers an out-of-bounds write of 4 attacker-controlled bytes past the end of a heap-allocated buffer. While the overflow is small, it can be leveraged for arbitrary code execution or a denial-of-service (crash). The vulnerability is fixed in version 2.4.67.
Affected products
- Apache HTTP Server through 2.4.66
- Red Hat Enterprise Linux 6, 7, 8, 9, 10.2
- Red Hat JBoss Core Services 1, 2.4.62.SP4
Timeline
- 2026-02-04: disclosed: Initial report to vendor
- 2026-05-05: advisory: Public disclosure by Apache and Openwall
- 2026-05-05: patched: Fixed in Apache HTTP Server 2.4.67
- 2026-05-27: patched: Red Hat released security updates (RHSA-2026:21391)
References
- https://httpd.apache.org/security/vulnerabilities_24.html
- http://www.openwall.com/lists/oss-security/2026/05/05/9
- https://access.redhat.com/errata/RHSA-2026:21391
- https://access.redhat.com/errata/RHSA-2026:21433
- https://access.redhat.com/errata/RHSA-2026:22140
- https://access.redhat.com/errata/RHSA-2026:27200
- https://access.redhat.com/errata/RHSA-2026:27201