DEV Community

StarkMan
StarkMan

Posted on

SNI, Host headers and the limits of name-based virtual hosting: CVE-2026-102795 explained

SNI, Host headers and the limits of name-based virtual hosting: CVE-2026-102795 explained

Overview

On 2 October 2026 the Apache Software Foundation published CVE-2026-102795 for Apache Traffic Server. The affected versions are 9.0.0 through 9.2.14 and 10.0.0 through 10.1.3; 9.2.15 and 10.1.4 contain the fix. The advisory describes an improper access control weakness in which a "SNI to Host header matching policy is not properly enforced".

Background: two ways of naming a site

Name-based virtual hosting in a TLS-terminating proxy depends on two separate pieces of information.
The SNI extension is presented during the handshake. It is not encrypted in a standard TLS 1.2 or TLS 1.3 handshake, and it is chosen by the client. The listener uses it to select a certificate and, usually, a configuration context.
The Host header is presented inside the HTTP request, after the secure channel exists. It is also chosen by the client.
Neither value is authoritative on its own. Their combined value comes from the expectation that a well-behaved client sends the same name in both places, and from the proxy's decision to reject requests where that expectation is violated. CVE-2026-102795 concerns that rejection step.

Mechanism and exploitation conditions

The published description is short and does not include a request-level walkthrough. What can be said with confidence is the precondition: the proxy must be expected to compare an SNI value with a Host value, and the client must be able to choose them independently. That situation arises in shared edges that serve multiple names.
Apache has not reported exploitation in the wild, and no public proof of concept is confirmed at the time of writing. Descriptions of this flaw should not be upgraded into claims of remote code execution.

Affected products and scope

All 9.x releases before 9.2.15 and all 10.x releases through 10.1.3 are affected. The record also supersedes CVE-2026-41920, which described the same weakness but with an incorrect version range and a misleading fix version.

Exposure context

ZoomEye matched 311,469 assets for app="Apache Traffic Server" on 3 October 2026. The companion query vul.cve="CVE-2026-102795" returned 0, which is typical immediately after disclosure. A fingerprint count measures where the software is visible; it does not measure which version each instance runs.

Remediation and mitigations

Upgrade to 9.2.15 or 10.1.4. Beyond the upgrade, the durable improvement is to reduce the number of names any single edge is willing to serve: explicit virtual hosts rather than catch-alls, a refusal as the default outcome for an unrecognised name, and a periodic review of which names are still expected to resolve.

References

  • SecurityOnline reporting on the Apache advisory batch, 3 October 2026
  • Apache Traffic Server download and release information

Top comments (0)