
CVE-2026-33267-PoC
CVE-2026-33267 — Apache Traffic Server @ header internal-metadata spoof (CVSS 10.0). Verified: @ headers leak to plugins on 10.1.2, stripped on 10.1.4
exploitationvulnerability-analysisweb-application-exploitation+1
4

CVE-2026-33267 — Apache Traffic Server @ header internal-metadata spoof (CVSS 10.0). Verified: @ headers leak to plugins on 10.1.2, stripped on 10.1.4

HTTP/2 Last Frame Synchronization (also known as Single Packet Attack) low Level Library / Tool based on Scapy + Exploit Timing Attacks

Exploit for Apache Solr remote code execution via Velocity template injection, enabling command execution on vulnerable instances through crafted…

Automated man-in-the-middle attack tool.