SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-33930

MEDIUM · CVSS 5.9 EPSS 0.38%

Source: NVD + CISA KEV + EPSS · Published 2026-07-29 · Last synced 2026-08-28

CyberRota Analysis

AI-Generated

Apache Traffic Server is vulnerable to a stack buffer overflow due to improper handling of the client Host header during redirect processing, which can be exploited if an overly long Host header is sent. This vulnerability could lead to potential denial-of-service conditions or arbitrary code execution. Organizations using affected versions (8.0.0 to 8.1.9, 9.0.0 to 9.2.14, 10.0.0 to 10.1.3) should prioritize upgrading to versions 9.2.15 or 10.1.4 to mitigate the risk.

CVE
CVE-2026-33930
Severity
MEDIUM
CVSS
5.9
EPSS
0.38%
Apache

Original NVD Description

Apache Traffic Server copies the client Host header into a fixed-size stack buffer without a bound during redirect handling, so an over-long Host header overflows the stack when redirect following is enabled. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.

Related CVEs

Other vulnerabilities affecting the same vendor(s)