Urgent.News

What's breaking now, across thousands of outlets.

Tech

SNI, Host headers and the limits of name-based virtual hosting: CVE-2026-102795 explained

SNI, Host headers and the limits of name-based virtual hosting: CVE-2026-102795 explained Overview On 2 October 2026 the Apache Software Foundation published CVE-2026-102795 for Apache Traffic Server. The affected versions are 9.0.0 through 9.2.14 and 10.0.0 through 10.1.3; 9.2.15 and 10.1.4 contain the fix. The advisory describes an improper access control weakness in which a "SNI to Host header…

Apache Traffic Server, a TLS-terminating proxy, is vulnerable to CVE-2026-102795 due to improper access control enforcement. This flaw arises from the inability to consistently compare SNI and Host header values, which are chosen independently by the client. The SNI extension, presented during the TLS handshake, helps in selecting a certificate and configuration context.

On the other hand, the Host header, included in the HTTP request, plays a role in determining the requested resource. An attacker can exploit this vulnerability to gain unauthorized access by manipulating these headers, provided the proxy is configured to serve multiple names on the same edge. Apache Traffic Server versions 9.0.0 through 9.2.14 and 10.0.0 through 10.1.3 are susceptible to this attack.

There have been no confirmed instances of exploitation in the wild, nor any publicly available proof-of-concept exploits. The vulnerability has been superseded by CVE-2026-41920, which had an incorrect version range and a misleading fix. To mitigate the risk, users are advised to upgrade to the latest versions, 9.2.15 or 10.1.4.

In addition, reducing the number of names served by a single edge, employing explicit virtual hosts, and regularly reviewing the list of expected names can enhance security.

Written by urgent.news from Dev.to's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at dev.to →

More in Tech

TypeBloom 🌸💮🪷

Saw a bunch of people sharing generative floral typography lately and loved the concept, so I decided to build my own version.

Building a Browser Pitch Detector (and Reusing It for a Guitar Tuner)

01 · Why this is harder than it looks Every musician has used a phone tuner app. Building one in the browser sounds straightforward: grab the mic, run FFT, show the note. Ship it.

  • Browser microphone features interfere with pitch detection
  • Three-layer pipeline includes mic input, audio graph, engine
  • React UI handles pitch display with throttled updates

35 free developer tools that run entirely in your browser — no signup, no uploads

Two things always bothered me about the usual "paste your JSON here" websites: half of them quietly upload your data to a server, and the other half drown you in ads.

  • JSON Formatter formats, validates, and minifies JSON locally in browser
  • JWT Decoder decodes authentication tokens without sharing sensitive data
  • Regex Tester provides live highlighting and capture groups for regex patterns

More from Saturday 10 October →