Junglewise Threat Intelligence

CVE-2026-24033: Apache Traffic Server HTTP request smuggling

CVE-2026-24033 · Severity: high · CVSS 7.2 · Published 2026-07-29

Technologies: Apache Traffic Server. Vendors: Apache.

Executive brief

Apache Traffic Server, a widely used caching proxy server that speeds up web content delivery, is vulnerable to a security flaw that allows attackers to interfere with how web requests are processed. By sending specially crafted messages, an attacker could potentially bypass security controls or gain unauthorized access to data by 'smuggling' hidden requests past the server's defenses. Organizations using affected versions should upgrade to the latest patched releases to ensure the integrity of their web traffic.

Technical details

Apache Traffic Server (ATS) is susceptible to an HTTP Request Smuggling vulnerability (CWE-444) caused by inconsistent interpretation of HTTP requests. This flaw allows a remote, unauthenticated attacker to send specially crafted HTTP requests that are parsed differently by ATS and the backend origin servers it protects. By exploiting this discrepancy, an attacker can 'smuggle' a hidden request inside a legitimate one, potentially leading to security filter bypass, unauthorized data access, or cache poisoning. The issue affects versions 9.0.0 through 9.2.14 and 10.0.0 through 10.1.3. Users are advised to upgrade to versions 9.2.15 or 10.1.4.

Affected products

  • Apache Traffic Server 10.0.0 through 10.1.3, 9.0.0 through 9.2.14

Timeline

  • 2026-07-29: advisory
  • 2026-07-29: patched: Fixed in versions 9.2.15 and 10.1.4

References