The Apache Software Foundation (ASF) has published a critical security update resolving a significant HTTP request smuggling and cache poisoning vulnerability in Apache Traffic Server (ATS) (tracked as CVE-2026-102795, CVSS 9.1). The flaw allows attackers to manipulate HTTP request boundaries, bypass upstream edge authentication filters, and poison reverse proxy cache stores with malicious payloads distributed globally across content delivery networks (CDNs).
Protocol Parsing Divergence & Smuggling Mechanics
Apache Traffic Server is widely deployed by telecommunications operators, cloud infrastructure providers, and high-volume websites as a caching forward and reverse proxy. ATS mediates client connections over HTTP/1.1 and HTTP/2, caching static and dynamic resources while routing upstream requests to origin web clusters.
The vulnerability stems from how ATS parses chunked transfer encoding headers containing trailing whitespace, obsolete line folding, or malformed chunk extensions. While upstream edge components (such as AWS CloudFront, Cloudflare, or F5 BIG-IP) strictly enforce RFC 9112 guidelines by stripping invalid chunk extensions, vulnerable versions of ATS leniently accepted ambiguous delimiters. This created a classic HTTP Request Smuggling (H2.CL / CL.TE) discrepancy between proxy layers.
POST /public/feed HTTP/1.1
Host: cdn.target-enterprise.com
Transfer-Encoding: chunked
Content-Length: 44
0
GET /admin/user-database HTTP/1.1
Host: internal-origin.corp
X-Forwarded-For: 127.0.0.1
Because ATS misinterpreted the chunk boundary, the secondary request (GET /admin/user-database) was left unread in the pipeline socket. When the subsequent innocent user request arrived on the shared connection, the internal origin server treated the smuggled request as the next pipeline query, serving confidential administrator data or caching the origin response under the innocent user's requested URL.
Global Cache Poisoning & Blast Radius
The most dangerous manifestation of CVE-2026-102795 is Web Cache Poisoning. By smuggling a request that triggers an error redirect or an attacker-controlled JavaScript resource, the proxy stores the malicious response in its local cache disk under high-traffic legitimate endpoints (such as /static/bundle.js or /logo.svg).
Subsequent web visitors around the world requesting the legitimate resource are served the poisoned cached object directly from the CDN edge without querying the origin server, leading to mass client-side code execution, session hijacking, or denial of service across entire customer bases.
Version Matrix & Affected Environments
| Release Branch | Vulnerable Versions | Fixed Version | Recommended Action |
|---|---|---|---|
| ATS 9.x Branch | 9.0.0 through 9.2.5 | 9.2.6 | Apply patch or upgrade package |
| ATS 10.x Branch | 10.0.0 | 10.0.1 | Immediate upgrade |
| Legacy 8.x Branch | All versions (End-of-Life) | None (Unsupported) | Migrate to ATS 9.2.6+ / 10.0.1+ |
Defensive Remediation Playbook
- Upgrade Apache Traffic Server: Install official binary releases or compile patched source archives for ATS
9.2.6or10.0.1. Verify your installed build using:# Check installed ATS daemon version traffic_server -V # Expected output: # Apache Traffic Server - traffic_server - 9.2.6 - (build ...) - Harden HTTP Strict Parsing in records.yaml: Ensure strict HTTP parsing standards are enforced in
records.yaml(orrecords.configfor ATS 9.x) to reject malformed chunked requests immediately:# Configure strict HTTP conformance in records.yaml records: http: server_session_sharing: match: both chunking_enabled: 1 strict_uri_parsing: 1 core: http: parse: strict: 1 - Purge Proxy Caches Globally: After deploying the update, execute a global cache purge to evict potentially poisoned objects from memory and disk storage:
# Invalidate entire ATS disk cache traffic_ctl server stop traffic_server -Cclear traffic_ctl server start



