An advisory published on October 2, 2026 reports a moderate access-control flaw in Apache Traffic Server, which does not correctly enforce the matching policy between SNI and the Host header.
The advisory describes CVE-2026-102795, an improper access-control flaw in Apache Traffic Server involving the match between SNI and the Host header. Affected versions are 9.0.0 through 9.2.14 and 10.0.0 through 10.1.3. The stated severity is moderate; the recommended fix is to upgrade to version 9.2.15 or 10.1.4.
Published on October 2, 2026, the notice says this CVE replaces CVE-2026-41920, but the available text does not detail the earlier record. Consult the original oss-sec notice and official Apache Traffic Server documentation to verify the scope and upgrade steps. Compare the installed version with the affected ranges and validate the fix after upgrading.