Permissive Regular Expression in Apache Traffic Server - CVE-2026-22068
Published: August 24, 2026
Vulnerability details
The vulnerability allows a remote attacker to bypass access controls.
The vulnerability exists due to improper regular expression handling in remap, SNI, and plugins when performing selection with unanchored regular expressions. A remote attacker can supply values that match substrings or suffixes to bypass access controls.
The issue affects ACL, SNI, signature, and geo controls.
Affected software
Fedora
trafficserver
How to mitigate CVE-2026-22068
trafficserver - addressed in versions 9.2.15-1.el8, 9.2.15-1.el9, 10.1.4-1.fc43, 10.1.4-1.fc44, 10.2.0-1.fc43