CVE-2026-24033: Apache Traffic Server: Request smuggling via chunked extension quoted-string parsing
Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') vulnerability in Apache Traffic Server.
This issue affects Apache Traffic Server: from 10.0.0 through 10.1.3, from 9.0.0 through 9.2.14.
Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fixes the issue.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Apache Traffic Serverto a version that resolves this vulnerability.Fixed in 9.2.15 - Upgrade
Upgrade
Apache Traffic Serverto a version that resolves this vulnerability.Fixed in 10.1.4
Event History
Frequently Asked Questions
What is the severity of CVE-2026-24033?
CVE-2026-24033 has a severity rating of 7.2, which is classified as high.
How do I fix CVE-2026-24033?
To fix CVE-2026-24033, users should upgrade to Apache Traffic Server version 9.2.15 or 10.1.4.
What is CVE-2026-24033?
CVE-2026-24033 is a vulnerability in Apache Traffic Server that allows request smuggling due to inconsistent HTTP request interpretation.
Which versions of Apache Traffic Server are affected by CVE-2026-24033?
Apache Traffic Server versions from 10.0.0 through 10.1.3 and from 9.0.0 through 9.2.14 are affected by CVE-2026-24033.
What vulnerability type is CVE-2026-24033?
CVE-2026-24033 is classified as an 'HTTP Request/Response Smuggling' vulnerability.