Out-of-bounds read in Apache HTTP Server - CVE-2026-33857
Published: May 4, 2026
Apache HTTP Server
Apache Foundation
Description
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to an out-of-bounds read in mod_proxy_ajp AJP getter functions when parsing AJP data. A remote attacker can send a specially crafted AJP message to disclose sensitive information.
Exploitation requires Apache HTTP Server to connect to an untrusted or compromised AJP backend server.