Stack-based buffer overflow in Apache Traffic Server - CVE-2026-33930
Published: August 24, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to stack-based buffer overflow in redirect handling when copying a client Host header into a fixed-size stack buffer. A remote attacker can send an over-long Host header to cause a denial of service.
The issue is triggered when redirect following is enabled.
Affected software
Fedora
trafficserver
How to mitigate CVE-2026-33930
trafficserver - addressed in versions 9.2.15-1.el8, 9.2.15-1.el9, 10.1.4-1.fc43, 10.1.4-1.fc44