Improper Certificate Validation in Apache Traffic Server - CVE-2026-65325
Published: August 24, 2026
Vulnerability details
The vulnerability allows a remote attacker to bypass certificate hostname validation.
The vulnerability exists due to improper certificate validation in HTTP/2 multiplexed origin session reuse when reusing origin connections for a new request hostname. A remote attacker can trigger reuse of an existing connection to bypass certificate hostname validation.
Affected software
Fedora
trafficserver
How to mitigate CVE-2026-65325
trafficserver - addressed in versions 9.2.15-1.el8, 9.2.15-1.el9, 10.1.4-1.fc43, 10.1.4-1.fc44