CVE-2026-24033

Apache Traffic Server: Request smuggling via chunked extension quoted-string parsing

Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') vulnerability in Apache Traffic Server. This issue affects Apache Traffic Server: from 10.0.0 through 10.1.3, from 9.0.0 through 9.2.14. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fixes the issue.


We have discovered 369 live websites that are affected by CVE-2026-24033.

Run a Free Instant Scan




Affected Software

Product  ATS
Category Web Servers
Vulnerable Domains369 live websites (35% of ATS install base)
Vulnerable Versions
  • from 9 through 9.2.14
  • from 10 through 10.1.3
Vulnerable Versions Count11 versions ( 44% of all versions)


Common Weakness Enumeration

CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')



Details

  • Published - Jul 29, 2026
  • Updated - Jul 29, 2026

Credits

  • Rajat Raghav (reporter)
  • Katsutoshi Ikenoya (LY Corporation) (reporter)

Website Distribution by Country

Number of websites using CVE-2026-24033
United States34 websites



Germany131 websites
China124 websites
GB36 websites
Isle of Man8 websites
Russia7 websites
Canada5 websites
Finland5 websites
Italy5 websites
France4 websites

Website Distribution by TLD

Number of websites using CVE-2026-24033
.com.cn88 websites
.com59 websites
.cn23 websites
.org22 websites
.de20 websites
.org.uk11 websites
.net10 websites
.it8 websites
.ru7 websites
.fi7 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2026-24033

Top websites that are affected by CVE-2026-24033. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
****.******.jp Japan**,***
***.**********.de Germany**,***
*********.******.***.cn China**,***
******.**********.de Germany***,***
******.***.cn China***,***
*****.******.***.cn China***,***
***.***.**.uk GB***,***
****.******.***.cn China***,***
*****.****.******.community Germany***,***
*****.****.******.community Germany***,***
See full domain list

FAQ

CVE-2026-24033 is Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') in ATS
A total of 369 websites have been identified as vulnerable to CVE-2026-24033, based on global website indexing conducted by WebTechSurvey.
The ATS is affected by the CVE-2026-24033 vulnerability.
ATS versions up to and including 10.1.3 are vulnerable to CVE-2026-24033.