目標達成 すべての支援者に感謝 — 100%達成しました!

目標: 1000 CNY · 調達済み: 1336 CNY

100%

CVE-2026-41920— Apache Traffic Server 权限许可和访问控制问题漏洞

CVSS 9.3 · Critical EPSS 0.30% · P22

Affected Version Matrix 2

ベンダープロダクトVersion Rangeステータス
Apache Software FoundationApache Traffic Server9.0.0≤ 9.1.14affected
10.0.0≤ 10.1.3affected
新しい脆弱性情報の通知を購読するログインして購読

I. CVE-2026-41920の基本情報

脆弱性情報

脆弱性についてご質問がありますか?Shenlongの分析が参考になるかご確認ください!
Shenlongの10の質問を表示 ↗

高度な大規模言語モデル技術を使用していますが、出力には不正確または古い情報が含まれる可能性があります。Shenlongはデータの正確性を確保するよう努めていますが、実際の状況に基づいて検証・判断してください。

脆弱性タイトル
Apache Traffic Server: SNI to Host header matching policy is not properly enforced
ソース: CVE Program / CVE List V5
脆弱性説明
Improper Access Control vulnerability in Apache Traffic Server. This issue affects Apache Traffic Server: from 9.0.0 through 9.1.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.1.15 or 10.1.4, which fixes the issue.
ソース: CVE Program / CVE List V5
CVSS情報
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:H/A:N
ソース: CVE Program / CVE List V5
脆弱性タイプ
访问控制不恰当
ソース: CVE Program / CVE List V5
脆弱性タイトル
Apache Traffic Server 权限许可和访问控制问题漏洞
ソース: CNNVD (China National Vulnerability Database)
脆弱性説明
Apache traffic server是美国Apache基金会开源的一个高性能HTTP代理服务器。 Apache Traffic Server 9.0.0版本至9.1.14版本和10.0.0版本至10.1.3版本存在权限许可和访问控制问题漏洞,该漏洞源于访问控制不当。
ソース: CNNVD (China National Vulnerability Database)
CVSS情報
N/A
ソース: CNNVD (China National Vulnerability Database)
脆弱性タイプ
N/A
ソース: CNNVD (China National Vulnerability Database)

影響を受ける製品

ベンダープロダクト影響を受けるバージョンCPE購読
Apache Software FoundationApache Traffic Server 9.0.0 ~ 9.1.14 -

II. CVE-2026-41920の公開POC

#POC説明ソースリンクShenlongリンク
AI生成POCプレミアム

公開POCは見つかりませんでした。

ログインしてAI POCを生成

III. CVE-2026-41920のインテリジェンス情報

登录查看更多情报信息。

Same Patch Batch · Apache Software Foundation · 2026-07-29 · 41 CVEs total

CVE-2026-3326710.0 CRITICALApache Traffic Server: Untrusted @ headers can spoof ATS internal metadata
CVE-2026-5816210.0 CRITICALApache Traffic Server: Certifier plugin trusts client SNI when generating certificates
CVE-2026-5815010.0 CRITICALApache Traffic Server: HTTP/2 requests with Transfer-Encoding are not rejected, allowing r
CVE-2026-5783410.0 CRITICALApache Traffic Server: Malformed chunked message body allows request smuggling
CVE-2026-581559.3 CRITICALApache Traffic Server: Header-name length truncation enables header aliasing and request s
CVE-2026-581548.9 HIGHApache Traffic Server: Memory-safety errors in MIME and header parsing
CVE-2026-581578.7 HIGHApache Traffic Server: Improper server-session reuse can expose data across client connect
CVE-2026-581828.6 HIGHApache Traffic Server: ts_lua plugin has initialization and resource-handling errors
CVE-2026-581538.3 HIGHApache Traffic Server: HTTP/2 to HTTP/1 conversion forwards origin trailers to clients uns
CVE-2026-220688.2 HIGHApache Traffic Server: Regex mappings match with malicious domain names
CVE-2026-581888.2 HIGHApache Traffic Server: Memory-safety and limit-bypass errors across experimental plugins
CVE-2026-581598.2 HIGHApache Traffic Server: Listener and ACL handling allow access-control bypass
CVE-2026-581848.2 HIGHApache Traffic Server: header_rewrite plugin cookie handling can corrupt memory
CVE-2026-581798.1 HIGHApache Traffic Server: regex_remap plugin overflows the stack from attacker input
CVE-2026-581778.1 HIGHApache Traffic Server: Memory-safety and path-traversal errors in the Cripts framework
CVE-2026-581867.5 HIGHApache Traffic Server: webp_transform plugin decodes unsafely and mislabels degraded respo
CVE-2026-653247.5 HIGHApache Traffic Server: HTTP/2 and HTTP/3 dechunking removes per-stream buffer cap, allowin
CVE-2026-581817.5 HIGHApache Traffic Server: uri_signing and url_sig plugins can exhaust the stack or crash
CVE-2026-581807.5 HIGHApache Traffic Server: txn_box plugin overflows the stack from attacker input
CVE-2026-581617.5 HIGHApache Traffic Server: Memory-safety errors in TLS and SNI handling can crash the server

Showing 20 of 41 CVEs. View all on vendor page →

IV. 関連脆弱性

V. CVE-2026-41920へのコメント

まだコメントはありません


コメントを残す