
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-33857 is an out-of-bounds read vulnerability in the mod_proxy_ajp module of Apache HTTP Server, specifically caused by off-by-one errors in AJP getter functions. It affects all versions of Apache HTTP Server through 2.4.66, and was reported on 2026-03-20 and fixed on 2026-05-04 with the release of version 2.4.67. IBM HTTP Server is also affected as a downstream product. The vulnerability carries a CVSS v3.1 base score of 5.3 (Medium) (GitHub Advisory, Openwall OSS-Sec).
The root cause is classified as CWE-125 (Out-of-bounds Read), arising from off-by-one errors in AJP getter functions within the mod_proxy_ajp module. An unauthenticated remote attacker can send crafted network requests over the AJP protocol to trigger the out-of-bounds read, potentially causing the server to disclose small amounts of memory contents. No authentication or user interaction is required, and attack complexity is low. The vulnerability was discovered by Elhanan Haenel and fixed in SVN revision r1933341 in the 2.4.x branch (Openwall OSS-Sec, GitHub Advisory).
Successful exploitation results in a limited confidentiality impact — an unauthenticated attacker can read small amounts of server memory, potentially exposing sensitive data processed by the AJP proxy module. There is no impact on integrity or availability. The scope is limited to the affected Apache HTTP Server instance, with no evidence of lateral movement potential directly from this vulnerability (GitHub Advisory, Apache Advisory).
There is no known public proof-of-concept exploit and no evidence of in-the-wild exploitation as of the time of disclosure. The EPSS score is approximately 0.10% (0.001030), indicating a low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported (GitHub Advisory, Openwall OSS-Sec).
The primary remediation is to upgrade Apache HTTP Server to version 2.4.67 or later, which contains the fix for this vulnerability. If an immediate upgrade is not feasible, administrators should consider disabling mod_proxy_ajp if it is not required for their deployment, or restricting network-level access to AJP ports (typically TCP 8009). IBM HTTP Server users should refer to IBM's security bulletin for applicable fixes. Downstream distributions including Debian, Ubuntu, Red Hat, SUSE, openSUSE, Amazon Linux, and Slackware have released updated packages (Apache Advisory, IBM Advisory, Ubuntu Advisory).
SecurityWeek covered the broader Apache HTTP Server 2.4.67 release, noting multiple critical and high-severity vulnerabilities patched alongside this issue (SecurityWeek). Heise reported on the release, highlighting the more severe flaws in the same advisory batch (Heise). The Qualys Threat Protect blog also covered the broader Apache HTTP Server advisory (Qualys Blog). Community reaction has been relatively muted given the medium severity rating and absence of active exploitation.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."