Incorrect Comparison in Apache Traffic Server - CVE-2026-41920
Published: August 24, 2026
Vulnerability details
The vulnerability allows a remote attacker to bypass host-SNI policy.
The vulnerability exists due to incorrect string comparison in TLS/SNI when comparing the TLS SNI against the Host header using a length taken from the Host alone. A remote attacker can send a specially crafted SNI value to bypass host-SNI policy.
Any SNI value that has the Host header as a prefix can trigger the issue.
Affected software
Fedora
trafficserver
How to mitigate CVE-2026-41920
trafficserver - addressed in versions 9.2.15-1.el8, 9.2.15-1.el9, 10.1.4-1.fc43, 10.1.4-1.fc44