AI and data stack advisories

Severe, 6 weeks2973Projects319

2973 severe, 6 weeks · 319 projects

Apache Traffic Server: improper access control

Apache Software Foundation

CVE-2026-102795 · Published Oct 2, 2026

High7.0
No fix yet

Improper Access Control vulnerability in Apache Traffic Server.

This issue affects Apache Traffic Server: from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3.

Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fixes the issue.

This CVE supersedes CVE-2026-41920, whose record listed the affected 9.x versions as 9.0.0 through 9.1.14 and the fixed version as 9.1.15. All 9.2.x releases before 9.2.15 are affected.

Affected versions

PackageAffectedFixed in
Apache Traffic Server
Product
>= 9.0.0, <= 9.2.14No fix yet
>= 10.0.0, <= 10.1.3No fix yet
Details and references
CVSS 4.0
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Severity from
the vendor (its own CVE record or advisory)
Weakness
CWE-284

More Apache Software Foundation advisories

All Apache Software Foundation
Advisory
Apache OpenOffice: code execution
High8.8Oct 2
Apache Thrift: improper exception handling
High8.7Oct 2
Uncaught exception vulnerability in Apache Thrift Perl bindings
High8.2Oct 2
Inefficient Algorithmic Complexity vulnerability in Apache Thrift Perl bindings
High8.2Oct 2
Apache Thrift: uncontrolled recursion
High8.2Oct 2
Inefficient Algorithmic Complexity vulnerability in Apache Thrift Lua bindings
High8.7Oct 2