CVE-2026-33857: Apache HTTP Server: Off-by-one OOB reads in AJP getter functions
Apache HTTP Server: Off-by-one OOB reads in AJP getter functions
Other sources
Out-of-bounds Read vulnerability in modproxyajp of
Apache HTTP Server.
This issue affects Apache HTTP Server: through 2.4.66.
Users are recommended to upgrade to version 2.4.67, which fixes the issue.
— NVD
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 2.4.67-1 - Upgrade
Upgrade
Apache HTTP Serverto a version that resolves this vulnerability.Fixed in 2.4.67Patch CVE-2026-33857
Event History
Frequently Asked Questions
What is the severity of CVE-2026-33857?
CVE-2026-33857 is classified as an Off-by-one Out-of-Bounds Read vulnerability in Apache HTTP Server.
How do I fix CVE-2026-33857?
To fix CVE-2026-33857, upgrade your Apache HTTP Server to version 2.4.67 or later.
Which versions of Apache HTTP Server are affected by CVE-2026-33857?
CVE-2026-33857 affects Apache HTTP Server versions up to and including 2.4.66.
What components of Apache HTTP Server are impacted by CVE-2026-33857?
The vulnerability CVE-2026-33857 specifically impacts the mod_proxy_ajp component of Apache HTTP Server.
Is there a workaround for CVE-2026-33857 if I cannot upgrade?
There are no known workarounds for CVE-2026-33857, so upgrading is the best mitigation.