CVE-2026-33930: Apache Traffic Server: Buffer overflow via Host field that has a long string value
Apache Traffic Server copies the client Host header into a fixed-size stack buffer without a bound during redirect handling, so an over-long Host header overflows the stack when redirect following is enabled.
This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3.
Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Apache Traffic Serverto a version that resolves this vulnerability.Fixed in 9.2.15 - Upgrade
Upgrade
Apache Traffic Serverto a version that resolves this vulnerability.Fixed in 10.1.4
Event History
Frequently Asked Questions
What is the severity of CVE-2026-33930?
CVE-2026-33930 has a medium severity score of 5.9.
How do I fix CVE-2026-33930?
To fix CVE-2026-33930, upgrade Apache Traffic Server to version 8.2.0 or later.
What impact does CVE-2026-33930 have on Apache Traffic Server?
CVE-2026-33930 can lead to a stack overflow, potentially causing a denial of service.
What versions of Apache Traffic Server are affected by CVE-2026-33930?
CVE-2026-33930 affects Apache Traffic Server versions from 8.0.0 to 8.1.9 and 9.0.0 to 9.2.x.
Is there a known exploit for CVE-2026-33930?
As of the latest information, there are no public exploits reported for CVE-2026-33930.