Critical severity9.8NVD Advisory· Published May 5, 2026· Updated Jul 28, 2026
CVE-2026-28780
CVE-2026-28780
Description
Heap-based Buffer Overflow vulnerability in mod_proxy_ajp of Apache HTTP Server. If mod_proxy_ajp connects to a malicious AJP server this AJP server can send a malicious AJP message back to mod_proxy_ajp and cause it to write 4 attacker controlled bytes after the end of a heap based buffer.
This issue affects Apache HTTP Server: through 2.4.66.
Users are recommended to upgrade to version 2.4.67, which fixes the issue.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
38cpe:2.3:a:apache:http_server:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:apache:http_server:*:*:*:*:*:*:*:*range: <2.4.67
- (no CPE)range: <=2.4.66
- osv-coords36 versionspkg:bitnami/apachepkg:rpm/almalinux/httpdpkg:rpm/almalinux/httpd-corepkg:rpm/almalinux/httpd-develpkg:rpm/almalinux/httpd-filesystempkg:rpm/almalinux/httpd-manualpkg:rpm/almalinux/httpd-toolspkg:rpm/almalinux/mod_http2pkg:rpm/almalinux/mod_ldappkg:rpm/almalinux/mod_luapkg:rpm/almalinux/mod_mdpkg:rpm/almalinux/mod_proxy_htmlpkg:rpm/almalinux/mod_sessionpkg:rpm/almalinux/mod_sslpkg:rpm/opensuse/apache2&distro=openSUSE%20Leap%2016.0pkg:rpm/opensuse/apache2&distro=openSUSE%20Tumbleweedpkg:rpm/opensuse/apache2-devel&distro=openSUSE%20Leap%2016.0pkg:rpm/opensuse/apache2-event&distro=openSUSE%20Leap%2016.0pkg:rpm/opensuse/apache2-manual&distro=openSUSE%20Leap%2016.0pkg:rpm/opensuse/apache2-prefork&distro=openSUSE%20Leap%2016.0pkg:rpm/opensuse/apache2-utils&distro=openSUSE%20Leap%2016.0pkg:rpm/opensuse/apache2-worker&distro=openSUSE%20Leap%2016.0pkg:rpm/suse/apache2&distro=SUSE%20Linux%20Enterprise%20Server%2016.0pkg:rpm/suse/apache2&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20applications%2016.0pkg:rpm/suse/apache2-devel&distro=SUSE%20Linux%20Enterprise%20Server%2016.0pkg:rpm/suse/apache2-devel&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20applications%2016.0pkg:rpm/suse/apache2-event&distro=SUSE%20Linux%20Enterprise%20Server%2016.0pkg:rpm/suse/apache2-event&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20applications%2016.0pkg:rpm/suse/apache2-manual&distro=SUSE%20Linux%20Enterprise%20Server%2016.0pkg:rpm/suse/apache2-manual&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20applications%2016.0pkg:rpm/suse/apache2-prefork&distro=SUSE%20Linux%20Enterprise%20Server%2016.0pkg:rpm/suse/apache2-prefork&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20applications%2016.0pkg:rpm/suse/apache2-utils&distro=SUSE%20Linux%20Enterprise%20Server%2016.0pkg:rpm/suse/apache2-utils&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20applications%2016.0pkg:rpm/suse/apache2-worker&distro=SUSE%20Linux%20Enterprise%20Server%2016.0pkg:rpm/suse/apache2-worker&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20applications%2016.0
< 2.4.67+ 35 more
- (no CPE)range: < 2.4.67
- (no CPE)range: < 2.4.62-13.el9_8.1
- (no CPE)range: < 2.4.62-13.el9_8.1
- (no CPE)range: < 2.4.62-13.el9_8.1
- (no CPE)range: < 2.4.62-13.el9_8.1
- (no CPE)range: < 2.4.62-13.el9_8.1
- (no CPE)range: < 2.4.62-13.el9_8.1
- (no CPE)range: < 1.15.7-10.module_el8.10.0+4185+0955a0d7.5
- (no CPE)range: < 2.4.62-13.el9_8.1
- (no CPE)range: < 2.4.62-13.el9_8.1
- (no CPE)range: < 1:2.0.8-8.module_el8.10.0+4088+57f011c1.2
- (no CPE)range: < 1:2.4.62-13.el9_8.1
- (no CPE)range: < 2.4.62-13.el9_8.1
- (no CPE)range: < 1:2.4.62-13.el9_8.1
- (no CPE)range: < 2.4.66-160000.2.1
- (no CPE)range: < 2.4.67-1.1
- (no CPE)range: < 2.4.66-160000.2.1
- (no CPE)range: < 2.4.66-160000.2.1
- (no CPE)range: < 2.4.66-160000.2.1
- (no CPE)range: < 2.4.66-160000.2.1
- (no CPE)range: < 2.4.66-160000.2.1
- (no CPE)range: < 2.4.66-160000.2.1
- (no CPE)range: < 2.4.66-160000.2.1
- (no CPE)range: < 2.4.66-160000.2.1
- (no CPE)range: < 2.4.66-160000.2.1
- (no CPE)range: < 2.4.66-160000.2.1
- (no CPE)range: < 2.4.66-160000.2.1
- (no CPE)range: < 2.4.66-160000.2.1
- (no CPE)range: < 2.4.66-160000.2.1
- (no CPE)range: < 2.4.66-160000.2.1
- (no CPE)range: < 2.4.66-160000.2.1
- (no CPE)range: < 2.4.66-160000.2.1
- (no CPE)range: < 2.4.66-160000.2.1
- (no CPE)range: < 2.4.66-160000.2.1
- (no CPE)range: < 2.4.66-160000.2.1
- (no CPE)range: < 2.4.66-160000.2.1
Patches
Vulnerability mechanics
References
14- www.openwall.com/lists/oss-security/2026/05/05/9nvdMailing ListThird Party Advisory
- httpd.apache.org/security/vulnerabilities_24.htmlnvdRelease NotesVendor Advisory
- access.redhat.com/errata/RHSA-2026:21391nvd
- access.redhat.com/errata/RHSA-2026:21433nvd
- access.redhat.com/errata/RHSA-2026:22140nvd
- access.redhat.com/errata/RHSA-2026:27200nvd
- access.redhat.com/errata/RHSA-2026:27201nvd
- access.redhat.com/errata/RHSA-2026:36373nvd
- access.redhat.com/errata/RHSA-2026:36831nvd
- access.redhat.com/errata/RHSA-2026:36846nvd
- access.redhat.com/errata/RHSA-2026:47046nvd
- access.redhat.com/security/cve/CVE-2026-28780nvd
- bugzilla.redhat.com/show_bug.cginvd
- security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-28780.jsonnvd
News mentions
1- Critical, High-Severity Vulnerabilities Patched in Apache MINA, HTTP ServerSecurityWeek · May 5, 2026