Buffer Overflow Vulnerability in Apache Traffic Server
CVE-2026-33930
8.2HIGH
What is CVE-2026-33930?
A buffer overflow vulnerability exists in Apache Traffic Server due to the improper handling of the client Host header during redirect processing. When redirect following is enabled, an excessively long Host header can overflow a fixed-size stack buffer, causing potential disruption or exploitation. It is crucial for users of affected versions to upgrade to 9.2.15 or 10.1.4 to mitigate this risk.
Affected Version(s)
Apache Traffic Server 8.0.0 <= 8.1.9
Apache Traffic Server 9.0.0 <= 9.2.14
Apache Traffic Server 10.0.0 <= 10.1.3