SNI, Host headers and the limits of name-based virtual hosting: CVE-2026-102795 explained
SNI, Host headers and the limits of name-based virtual hosting: CVE-2026-102795 explained Overview On 2 October 2026 the Apache Software Foundation published CVE-2026-102795 for Apache Traffic Server. The affected versions are 9.0.0 through 9.2.14 and 10.0.0 through 10.1.3; 9.2.15 and 10.1.4 contain the fix. The advisory describes an improper access control weakness in which a "SNI to Host header…
Apache Traffic Server, a TLS-terminating proxy, is vulnerable to CVE-2026-102795 due to improper access control enforcement. This flaw arises from the inability to consistently compare SNI and Host header values, which are chosen independently by the client. The SNI extension, presented during the TLS handshake, helps in selecting a certificate and configuration context.
On the other hand, the Host header, included in the HTTP request, plays a role in determining the requested resource. An attacker can exploit this vulnerability to gain unauthorized access by manipulating these headers, provided the proxy is configured to serve multiple names on the same edge. Apache Traffic Server versions 9.0.0 through 9.2.14 and 10.0.0 through 10.1.3 are susceptible to this attack.
There have been no confirmed instances of exploitation in the wild, nor any publicly available proof-of-concept exploits. The vulnerability has been superseded by CVE-2026-41920, which had an incorrect version range and a misleading fix. To mitigate the risk, users are advised to upgrade to the latest versions, 9.2.15 or 10.1.4.
In addition, reducing the number of names served by a single edge, employing explicit virtual hosts, and regularly reviewing the list of expected names can enhance security.
Written by urgent.news from Dev.to's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.