CVE-2026-28780: A heap-based buffer overflow in Apache's mod_proxy_ajp module that can lead to a server crash or potential remote code execution.
CVE-2026-29168: A resource exhaustion flaw in the mod_md module where unthrottled OCSP response data can cause a Denial of Service (DoS).
CVE-2026-29169: A NULL pointer dereference in the mod_dav_lock module that allows attackers to crash the specific worker process via malicious WebDAV requests.
CVE-2026-33006: A timing attack vulnerability in mod_auth_digest that allows remote attackers to bypass Digest authentication entirely.
CVE-2026-33007: A NULL pointer dereference in mod_authn_socache that enables unauthenticated remote users to crash a child process in a caching forward proxy configuration.
CVE-2026-33523: An HTTP response splitting vulnerability involving untrusted backend servers that facilitates Web Cache Poisoning or Cross-Site Scripting (XSS).
CVE-2026-33857: An out-of-bounds read flaw in mod_proxy_ajp that leaks adjacent, potentially sensitive memory contents back to the attacker.
CVE-2026-34032: An improper null termination bug in mod_proxy_ajp that causes indefinite memory reading, leading to server crashes or data leaks.
CVE-2026-34059: A core buffer over-read vulnerability triggered by complex URIs that exposes sensitive fragments of server memory.
Broadcom is aware of CVE-2026-28780, CVE-2026-29168, CVE-2026-29169, CVE-2026-33006, CVE-2026-33007, CVE-2026-33523, CVE-2026-33857, CVE-2026-34032 and CVE-2026-34059.
Please refer to the release notes for existing and forthcoming product releases for any updates in relation to this CVE. If you require further information please contact Broadcom Support
https://nvd.nist.gov/vuln/detail/CVE-2026-28780
https://nvd.nist.gov/vuln/detail/CVE-2026-29168
https://nvd.nist.gov/vuln/detail/CVE-2026-29169
https://nvd.nist.gov/vuln/detail/CVE-2026-33006
https://nvd.nist.gov/vuln/detail/CVE-2026-33007
https://nvd.nist.gov/vuln/detail/CVE-2026-33523
https://nvd.nist.gov/vuln/detail/CVE-2026-33857