Out-of-bounds read in Apache HTTP Server - CVE-2026-34032
Published: May 4, 2026
Apache HTTP Server
Apache Foundation
Description
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to improper null termination leading to an out-of-bounds read in mod_proxy_ajp ajp_msg_get_string when parsing AJP string data. A remote attacker can send a specially crafted AJP message to disclose sensitive information.
Exploitation requires Apache HTTP Server to connect to an untrusted or compromised AJP backend server.