CVE-2026-33267 is an Improper Input Validation vulnerability in Apache Traffic Server (ATS) in which untrusted @ headers in HTTP requests can be used to spoof ATS internal metadata, affecting versions 9.2.0 through 9.2.14 and 10.1.0 through 10.1.3. The flaw carries a perfect CVSS 3.1 score of 10.0 (Critical) and is exploitable remotely by unauthenticated attackers with no user interaction required. Apache has released fixed versions 9.2.15 and 10.1.4 and recommends immediate upgrade.
