tag
Traffic-Server
CVE-2026-33267 / GHSA-jrh6-9hgv-mqm7
web
CRITICAL 10
Apache Traffic Server Internal @Header Metadata Spoofing (CVE-2026-33267)
CVE-2026-33267 is an internal metadata spoofing vulnerability in Apache Traffic Server. ATS uses @-prefixed headers (e.g., @Ats-Internal, @ICAP-Status, @TCPInfo) as internal metadata that lives in the in-memory header structure but is never serialized on the…
Unverified
2026-08-16