Junglewise Threat Intelligence

CVE-2026-33267: Apache Traffic Server improper input validation

CVE-2026-33267 · Severity: critical · CVSS 10 · Published 2026-07-29

Technologies: Apache Traffic Server. Vendors: Apache.

Executive brief

Apache Traffic Server, a high-performance caching proxy used to manage web traffic and speed up content delivery, contains a critical security vulnerability. This flaw allows remote attackers to bypass security checks by sending specially crafted data that the system fails to validate correctly. Exploitation could lead to unauthorized access to sensitive data or the ability to modify web traffic, potentially compromising customer information and the integrity of the network.

Technical details

A critical improper input validation vulnerability (CWE-20) exists in Apache Traffic Server. The flaw allows a remote, unauthenticated attacker to bypass security constraints via the network. According to the CVSS 3.1 vector, the vulnerability has a high impact on confidentiality and integrity and involves a scope change, suggesting it may affect backend systems or other components beyond the proxy itself. The issue affects versions 9.2.0 through 9.2.14 and 10.1.0 through 10.1.3. Users are advised to upgrade to versions 9.2.15 or 10.1.4 to mitigate the risk.

Affected products

  • Apache Traffic Server 9.2.0 to 9.2.14, 10.1.0 to 10.1.3

Timeline

  • 2026-07-29: disclosed
  • 2026-07-29: advisory

References

Related threats