ZDI-26-356: Apache HTTP Server mod_proxy_ajp Out-Of-Bounds Read Information Disclosure Vulnerability
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Apache HTTP Server. An attacker must first obtain the ability to compromise an AJP backend associated with the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 3.7. The following CVEs are assigned: CVE-2026-34032.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-26-356?
The severity of ZDI-26-356 is rated 24, indicating a high risk of information disclosure.
How do I fix ZDI-26-356?
To fix ZDI-26-356, you should update your Apache HTTP Server to the latest version that addresses this vulnerability.
What systems are affected by ZDI-26-356?
ZDI-26-356 affects installations of Apache HTTP Server that utilize mod_proxy_ajp.
What types of information could be disclosed by exploiting ZDI-26-356?
Exploiting ZDI-26-356 could allow attackers to disclose sensitive information stored on the affected Apache HTTP Server.
Is authentication required to exploit ZDI-26-356?
An attacker must have the ability to compromise an AJP backend associated with the target system to exploit ZDI-26-356.