Skip to content
CVSS 10.0CVSS 10.0 · CRITICAL

CVE-2026-33267Ejecución de código remoto en Apache Traffic Server

Improper Input Validation vulnerability in Apache Traffic Server. This issue affects Apache Traffic Server: from 9.2.0 through 9.2.14, from 10.1.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fixes the issue.

Ver en NVD

Análisis

Apache Traffic Server presenta una vulnerabilidad crítica de validación de entrada que permite a un atacante no autenticado comprometer totalmente el servidor. Este componente se utiliza habitualmente como proxy inverso y caché en infraestructuras de alto tráfico. Es fundamental actualizar a las versiones 9.2.15 o 10.1.4 para evitar posibles ataques de ejecución de código remoto.

Roles relevantes

BackendCloudLinuxCyberSecurity

Severidad

Puntaje: 10.0(CRITICAL)
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N
AV: NETWORK
AC: LOW
PR: NONE
UI: NONE
S: CHANGED
C: HIGH
I: HIGH
A: NONE
Tipo de falla (CWE): CWE-20

EPSS

Sin puntaje EPSS aún (CVE muy reciente).

Descripción técnica

Improper Input Validation vulnerability in Apache Traffic Server. This issue affects Apache Traffic Server: from 9.2.0 through 9.2.14, from 10.1.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fixes the issue.

Publicada: 29/7/2026, 8:16:30
Última modificación: 29/7/2026, 8:16:30

Referencias

InicioEventosBlogRecursosCursosEquipo