CVE-2026-33857
Apache HTTP Server vulnerability analysis and mitigation

Overview

CVE-2026-33857 is an out-of-bounds read vulnerability in the mod_proxy_ajp module of Apache HTTP Server, specifically caused by off-by-one errors in AJP getter functions. It affects all versions of Apache HTTP Server through 2.4.66, and was reported on 2026-03-20 and fixed on 2026-05-04 with the release of version 2.4.67. IBM HTTP Server is also affected as a downstream product. The vulnerability carries a CVSS v3.1 base score of 5.3 (Medium) (GitHub Advisory, Openwall OSS-Sec).

Technical details

The root cause is classified as CWE-125 (Out-of-bounds Read), arising from off-by-one errors in AJP getter functions within the mod_proxy_ajp module. An unauthenticated remote attacker can send crafted network requests over the AJP protocol to trigger the out-of-bounds read, potentially causing the server to disclose small amounts of memory contents. No authentication or user interaction is required, and attack complexity is low. The vulnerability was discovered by Elhanan Haenel and fixed in SVN revision r1933341 in the 2.4.x branch (Openwall OSS-Sec, GitHub Advisory).

Impact

Successful exploitation results in a limited confidentiality impact — an unauthenticated attacker can read small amounts of server memory, potentially exposing sensitive data processed by the AJP proxy module. There is no impact on integrity or availability. The scope is limited to the affected Apache HTTP Server instance, with no evidence of lateral movement potential directly from this vulnerability (GitHub Advisory, Apache Advisory).

Exploitability

There is no known public proof-of-concept exploit and no evidence of in-the-wild exploitation as of the time of disclosure. The EPSS score is approximately 0.10% (0.001030), indicating a low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported (GitHub Advisory, Openwall OSS-Sec).

Mitigation and workarounds

The primary remediation is to upgrade Apache HTTP Server to version 2.4.67 or later, which contains the fix for this vulnerability. If an immediate upgrade is not feasible, administrators should consider disabling mod_proxy_ajp if it is not required for their deployment, or restricting network-level access to AJP ports (typically TCP 8009). IBM HTTP Server users should refer to IBM's security bulletin for applicable fixes. Downstream distributions including Debian, Ubuntu, Red Hat, SUSE, openSUSE, Amazon Linux, and Slackware have released updated packages (Apache Advisory, IBM Advisory, Ubuntu Advisory).

Community reactions

SecurityWeek covered the broader Apache HTTP Server 2.4.67 release, noting multiple critical and high-severity vulnerabilities patched alongside this issue (SecurityWeek). Heise reported on the release, highlighting the more severe flaws in the same advisory batch (Heise). The Qualys Threat Protect blog also covered the broader Apache HTTP Server advisory (Qualys Blog). Community reaction has been relatively muted given the medium severity rating and absence of active exploitation.

Additional resources


SourceThis report was generated using AI

Related Apache HTTP Server vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-44631CRITICAL9.8
  • Apache HTTP Server logoApache HTTP Server
  • httpd:2.4::mod_proxy_html
NoYesJun 08, 2026
CVE-2026-49975HIGH7.5
  • NGINX logoNGINX
  • nginx
NoYesJun 08, 2026
CVE-2026-48913HIGH7.3
  • Apache HTTP Server logoApache HTTP Server
  • mod_ssl
NoYesJun 08, 2026
CVE-2026-44186HIGH7.3
  • Apache HTTP Server logoApache HTTP Server
  • apache2-prefork
NoYesJun 08, 2026
CVE-2026-44185HIGH7.3
  • Apache HTTP Server logoApache HTTP Server
  • apache2
NoYesJun 08, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management