What is CVE-2026-33930?
CVE-2026-33930 is a stack buffer overflow vulnerability in Apache Traffic Server caused by copying the client Host header into a fixed-size buffer without bounds checking during redirect handling. This can lead to remote code execution when redirect following is enabled. Affected versions 8.0.0-8.1.9 and 9.0.0-9.2 must be updated immediately.
Azərbaycanca: CVE-2026-33930 Apache Traffic Server-də redirect emalı zamanı Host başlığının hədd yoxlanılmadan fixed-size stack buffer-ə kopyalanması nəticəsində yaranan buffer overflow zəifliyidir. Bu, xüsusilə redirect following aktiv olduqda, uzaqdan kod icrasına səbəb ola bilər. Təsirə məruz qalan 8.0.0-8.1.9 və 9.0.0-9.2 versiyaları dərhal yenilənməlidir.
Related CVEs
link basis: same weakness class CWE-119; shared vendor: Apache
FAQ2
In which functionality of Apache Traffic Server does CVE-2026-33930 become exploitable?
The vulnerability becomes exploitable during redirect handling when the redirect following feature is enabled.
Which versions are affected by CVE-2026-33930?
Apache Traffic Server versions from 8.0.0 to 8.1.9, and from 9.0.0 to 9.2 are affected.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.