The Apache Software Foundation (ASF) has published a critical security update resolving a significant HTTP request smuggling and cache poisoning vulnerability in Apache Traffic Server (ATS) (tracked as CVE-2026-102795, CVSS 9.1). The flaw allows attackers to manipulate HTTP request boundaries, bypass upstream edge authentication filters, and poison reverse proxy cache stores with malicious payloads distributed globally across content delivery networks (CDNs).

Protocol Parsing Divergence & Smuggling Mechanics

Apache Traffic Server is widely deployed by telecommunications operators, cloud infrastructure providers, and high-volume websites as a caching forward and reverse proxy. ATS mediates client connections over HTTP/1.1 and HTTP/2, caching static and dynamic resources while routing upstream requests to origin web clusters.

The vulnerability stems from how ATS parses chunked transfer encoding headers containing trailing whitespace, obsolete line folding, or malformed chunk extensions. While upstream edge components (such as AWS CloudFront, Cloudflare, or F5 BIG-IP) strictly enforce RFC 9112 guidelines by stripping invalid chunk extensions, vulnerable versions of ATS leniently accepted ambiguous delimiters. This created a classic HTTP Request Smuggling (H2.CL / CL.TE) discrepancy between proxy layers.

POST /public/feed HTTP/1.1
Host: cdn.target-enterprise.com
Transfer-Encoding: chunked
Content-Length: 44

0
GET /admin/user-database HTTP/1.1
Host: internal-origin.corp
X-Forwarded-For: 127.0.0.1

Because ATS misinterpreted the chunk boundary, the secondary request (GET /admin/user-database) was left unread in the pipeline socket. When the subsequent innocent user request arrived on the shared connection, the internal origin server treated the smuggled request as the next pipeline query, serving confidential administrator data or caching the origin response under the innocent user's requested URL.

Global Cache Poisoning & Blast Radius

The most dangerous manifestation of CVE-2026-102795 is Web Cache Poisoning. By smuggling a request that triggers an error redirect or an attacker-controlled JavaScript resource, the proxy stores the malicious response in its local cache disk under high-traffic legitimate endpoints (such as /static/bundle.js or /logo.svg).

Subsequent web visitors around the world requesting the legitimate resource are served the poisoned cached object directly from the CDN edge without querying the origin server, leading to mass client-side code execution, session hijacking, or denial of service across entire customer bases.

Version Matrix & Affected Environments

Release Branch Vulnerable Versions Fixed Version Recommended Action
ATS 9.x Branch 9.0.0 through 9.2.5 9.2.6 Apply patch or upgrade package
ATS 10.x Branch 10.0.0 10.0.1 Immediate upgrade
Legacy 8.x Branch All versions (End-of-Life) None (Unsupported) Migrate to ATS 9.2.6+ / 10.0.1+

Defensive Remediation Playbook

  1. Upgrade Apache Traffic Server: Install official binary releases or compile patched source archives for ATS 9.2.6 or 10.0.1. Verify your installed build using:
    # Check installed ATS daemon version
    traffic_server -V
    
    # Expected output:
    # Apache Traffic Server - traffic_server - 9.2.6 - (build ...)
  2. Harden HTTP Strict Parsing in records.yaml: Ensure strict HTTP parsing standards are enforced in records.yaml (or records.config for ATS 9.x) to reject malformed chunked requests immediately:
    # Configure strict HTTP conformance in records.yaml
    records:
      http:
        server_session_sharing:
          match: both
        chunking_enabled: 1
        strict_uri_parsing: 1
      core:
        http:
          parse:
            strict: 1
  3. Purge Proxy Caches Globally: After deploying the update, execute a global cache purge to evict potentially poisoned objects from memory and disk storage:
    # Invalidate entire ATS disk cache
    traffic_ctl server stop
    traffic_server -Cclear
    traffic_ctl server start