CVE-2026-41920: Apache Traffic Server: SNI to Host header matching policy is not properly enforced
Improper Access Control vulnerability in Apache Traffic Server.
This issue affects Apache Traffic Server: from 9.0.0 through 9.1.14, from 10.0.0 through 10.1.3.
Users are recommended to upgrade to version 9.1.15 or 10.1.4, which fixes the issue.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Apache Traffic Serverto a version that resolves this vulnerability.Fixed in 9.1.15 - Upgrade
Upgrade
Apache Traffic Serverto a version that resolves this vulnerability.Fixed in 10.1.4
Event History
Frequently Asked Questions
What is the severity of CVE-2026-41920?
CVE-2026-41920 has a critical severity rating of 9.3.
How do I fix CVE-2026-41920?
To fix CVE-2026-41920, upgrade to Apache Traffic Server version 9.1.15 or 10.1.4.
What is the impact of CVE-2026-41920?
CVE-2026-41920 allows for improper access control, potentially leading to unauthorized access.
Which versions of Apache Traffic Server are affected by CVE-2026-41920?
CVE-2026-41920 affects Apache Traffic Server versions from 9.0.0 to 9.1.14 and from 10.0.0 to 10.1.3.
When was CVE-2026-41920 published?
CVE-2026-41920 was published on July 29, 2026.