CVE-2026-33267
Improper Input Validation vulnerability in Apache Traffic Server. This issue affects Apache Traffic Server: from 9.2.0 through 9.2.14, from 10.1.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fixes the issue.
- Affected products
- Apache Traffic Server
- Apache Traffic Server
- < 9.2.15, 10.1.4
- CVSS 3.1
- 10.0 CRITICAL
- EPSS
- 0.3% (26th percentile)
- Weakness
- CWE-20
- NVD status
- Analyzed
- Published
- 2026-07-29
CVE-2026-33267 at NVD
1 known exploit for CVE-2026-33267
Proof-of-concept code and exploit modules indexed by Sploitus