ZDI-CAN-30089: ZDI-26-356: Apache HTTP Server mod_proxy_ajp Out-Of-Bounds Read Information Disclosure Vulnerability
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Apache HTTP Server. An attacker must first obtain the ability to compromise an AJP backend associated with the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 3.7. The following CVEs are assigned: CVE-2026-34032.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-CAN-30089?
The severity of ZDI-CAN-30089 is rated at 18.
How do I fix ZDI-CAN-30089?
To fix ZDI-CAN-30089, ensure your installation of Apache HTTP Server is updated to the latest version that addresses this vulnerability.
What types of systems are impacted by ZDI-CAN-30089?
ZDI-CAN-30089 affects installations of Apache HTTP Server that utilize mod_proxy_ajp.
What does the ZDI-CAN-30089 vulnerability allow attackers to do?
ZDI-CAN-30089 allows remote attackers to disclose sensitive information from affected installations of Apache HTTP Server.
What is required for an attacker to exploit ZDI-CAN-30089?
An attacker must gain the ability to compromise an AJP backend associated with the target system in order to exploit ZDI-CAN-30089.