CVE-2026-34059: Apache HTTP Server: mod_proxy_ajp: Heap Over-Read and memory disclosure in ajp_parse_data()
Apache HTTP Server: modproxyajp: Heap Over-Read and memory disclosure in ajpparsedata()
Other sources
Buffer Over-read vulnerability in Apache HTTP Server.
This issue affects Apache HTTP Server: through 2.4.66.
Users are recommended to upgrade to version 2.4.67, which fixes the issue.
— NVD
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 2.4.67-1 - Upgrade
Upgrade
Apache HTTP Server (mod_proxy_ajp)to a version that resolves this vulnerability.Fixed in 2.4.67Patch CVE-2026-34059
Event History
Frequently Asked Questions
What is the severity of CVE-2026-34059?
CVE-2026-34059 is classified as a high-severity vulnerability due to its potential for heap over-read and memory disclosure.
How do I fix CVE-2026-34059?
To fix CVE-2026-34059, users should upgrade Apache HTTP Server to version 2.4.67 or later.
What versions of Apache HTTP Server are affected by CVE-2026-34059?
CVE-2026-34059 affects Apache HTTP Server versions up to and including 2.4.66.
What specific component is vulnerable in CVE-2026-34059?
The vulnerability in CVE-2026-34059 is found in the mod_proxy_ajp component of Apache HTTP Server.
What impact does CVE-2026-34059 have on systems?
CVE-2026-34059 can lead to memory disclosure, which may expose sensitive data from the affected system.