CVE-2026-102795: access control flaw in Apache Traffic Server
Apache Traffic Server has an improper access control flaw tied to SNI-to-Host header matching policy. Versions 9.0.0–9.2.14 and 10.0.0–10.1.3 are affected; fixes ship in 9.2.15 and 10.1.4. No exploitation in the wild has been reported, while ZoomEye counted 311,469 exposed instances.
- Affected branches: 9.0.0–9.2.14 and 10.0.0–10.1.3; fixes in 9.2.15 and 10.1.4
- Flaw lies in SNI-to-Host header matching policy
- ZoomEye found 311,469 Apache Traffic Server instances on 3 October 2026
- No in-the-wild exploitation or public proof of concept reported
Read next
Security