Apache HTTP Server is a powerful and flexible HTTP/1.1 compliant web server.
Security Fix(es):
Heap-based Buffer Overflow vulnerability in modproxyajp of Apache HTTP Server. If modproxyajp connects to a malicious AJP server this AJP server can send a malicious AJP message back to modproxyajp and cause it to write 4 attacker controlled bytes after the end of a heap based buffer.
This issue affects Apache HTTP Server: through 2.4.66.
Users are recommended to upgrade to version 2.4.67, which fixes the issue.(CVE-2026-28780)
{
"severity": "Critical"
}{
"src": [
"httpd-2.4.43-33.oe2003sp4.src.rpm"
],
"aarch64": [
"httpd-2.4.43-33.oe2003sp4.aarch64.rpm",
"httpd-debuginfo-2.4.43-33.oe2003sp4.aarch64.rpm",
"httpd-debugsource-2.4.43-33.oe2003sp4.aarch64.rpm",
"httpd-devel-2.4.43-33.oe2003sp4.aarch64.rpm",
"httpd-tools-2.4.43-33.oe2003sp4.aarch64.rpm",
"mod_ldap-2.4.43-33.oe2003sp4.aarch64.rpm",
"mod_md-2.4.43-33.oe2003sp4.aarch64.rpm",
"mod_proxy_html-2.4.43-33.oe2003sp4.aarch64.rpm",
"mod_session-2.4.43-33.oe2003sp4.aarch64.rpm",
"mod_ssl-2.4.43-33.oe2003sp4.aarch64.rpm"
],
"x86_64": [
"httpd-2.4.43-33.oe2003sp4.x86_64.rpm",
"httpd-debuginfo-2.4.43-33.oe2003sp4.x86_64.rpm",
"httpd-debugsource-2.4.43-33.oe2003sp4.x86_64.rpm",
"httpd-devel-2.4.43-33.oe2003sp4.x86_64.rpm",
"httpd-tools-2.4.43-33.oe2003sp4.x86_64.rpm",
"mod_ldap-2.4.43-33.oe2003sp4.x86_64.rpm",
"mod_md-2.4.43-33.oe2003sp4.x86_64.rpm",
"mod_proxy_html-2.4.43-33.oe2003sp4.x86_64.rpm",
"mod_session-2.4.43-33.oe2003sp4.x86_64.rpm",
"mod_ssl-2.4.43-33.oe2003sp4.x86_64.rpm"
],
"noarch": [
"httpd-filesystem-2.4.43-33.oe2003sp4.noarch.rpm",
"httpd-help-2.4.43-33.oe2003sp4.noarch.rpm"
]
}