CVE-2026-33267

Apache Traffic Server: Untrusted @ headers can spoof ATS internal metadata

Improper Input Validation vulnerability in Apache Traffic Server. This issue affects Apache Traffic Server: from 9.2.0 through 9.2.14, from 10.1.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fixes the issue.


We have discovered 201 live websites that are affected by CVE-2026-33267.

Run a Free Instant Scan




Affected Software

Product  ATS
Category Web Servers
Vulnerable Domains201 live websites (19% of ATS install base)
Vulnerable Versions
  • from 9.2 through 9.2.14
  • from 10.1 through 10.1.3
Vulnerable Versions Count6 versions ( 24% of all versions)


Common Weakness Enumeration

CWE-20 Improper Input Validation



Details

  • Published - Jul 29, 2026
  • Updated - Jul 30, 2026

Credits

  • Charlie Campbell (reporter)
  • Apache Community (reporter)

Website Distribution by Country

Number of websites using CVE-2026-33267
United States19 websites



Germany120 websites
GB36 websites
Italy5 websites
Russia5 websites
France4 websites
Bulgaria3 websites
China2 websites
Japan2 websites
Brazil1 websites

Website Distribution by TLD

Number of websites using CVE-2026-33267
.com23 websites
.org21 websites
.de17 websites
.org.uk11 websites
.it8 websites
.net6 websites
.ru5 websites
.pl2 websites
.be1 websites
.ch1 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2026-33267

Top websites that are affected by CVE-2026-33267. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
****.******.jp Japan**,***
***.**********.de Germany**,***
******.**********.de Germany***,***
***.***.**.uk GB***,***
*****.****.******.community Germany***,***
*****.****.******.community Germany***,***
*****.****.******.community Germany***,***
****.******.community Germany***,***
****.*************.******.org United States***,***
********.********.net United States***,***
See full domain list

FAQ

CVE-2026-33267 is Improper Input Validation in ATS
A total of 201 websites have been identified as vulnerable to CVE-2026-33267, based on global website indexing conducted by WebTechSurvey.
The ATS is affected by the CVE-2026-33267 vulnerability.
ATS versions up to and including 10.1.3 are vulnerable to CVE-2026-33267.