Description
Improper Input Validation vulnerability in Apache Traffic Server.

This issue affects Apache Traffic Server: from 9.2.0 through 9.2.14, from 10.1.0 through 10.1.3.

Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fixes the issue.
Published: 2026-07-29
Score: 7.7 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Apache Traffic Server has a flaw that accepts HTTP request headers beginning with the '@' character without sanitizing them. This improper input validation could allow an attacker to insert internal metadata that the server normally trusts only from internal sources. The vulnerability is classified as CWE‑20, and the CVE description does not explicitly state the exact consequences that could result from such metadata spoofing.

Affected Systems

Apache Traffic Server versions 9.2.0 through 9.2.14 and 10.1.0 through 10.1.3 are vulnerable. Users should verify the exact version in use and upgrade to the fixed releases 9.2.15 or 10.1.4.

Risk and Exploitability

The CVSS score of 7.7 reflects moderate‑to‑high severity. The EPSS score of less than 1% suggests a low probability of active exploitation at present. The flaw can be triggered by HTTP requests that contain malicious '@' headers; this attack vector is inferred from the nature of the input validation weakness and is not explicitly stated in the CVE. The vulnerability is not listed in the CISA KEV catalog, indicating no known public exploitation.

Generated by OpenCVE AI on August 12, 2026 at 01:36 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Apache Traffic Server to version 9.2.15 or 10.1.4, which includes the fix for the '@' header validation issue.
  • If an upgrade is not immediately possible, configure the front‑end load balancer or firewall to block or strip headers that start with the '@' character before they reach the server.
  • Monitor inbound HTTP traffic for suspicious '@' headers and audit logs for any unexpected internal metadata usage.

Generated by OpenCVE AI on August 12, 2026 at 01:36 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 29 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 29 Jul 2026 08:45:00 +0000

Type Values Removed Values Added
First Time appeared Apache
Apache traffic Server
Vendors & Products Apache
Apache traffic Server

Wed, 29 Jul 2026 07:45:00 +0000

Type Values Removed Values Added
Description Improper Input Validation vulnerability in Apache Traffic Server. This issue affects Apache Traffic Server: from 9.2.0 through 9.2.14, from 10.1.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fixes the issue.
Title Apache Traffic Server: Untrusted @ headers can spoof ATS internal metadata
Weaknesses CWE-20
References
Metrics cvssV3_1

{'score': 10, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N'}

cvssV4_0

{'score': 7.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:H/SA:N'}


Subscriptions

Apache Traffic Server
cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published:

Updated: 2026-07-30T03:55:17.126Z

Reserved: 2026-03-18T15:36:26.858Z

Link: CVE-2026-33267

cve-icon Vulnrichment

Updated: 2026-07-29T13:13:07.687Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-29T08:16:30.983

Modified: 2026-08-05T18:35:55.760

Link: CVE-2026-33267

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-12T01:45:04Z

Weaknesses