Apache Traffic Server security advisories

Security information for Apache Traffic Server

Reporting

Do you want disclose a potential security issue for Apache Traffic Server? Send your report to the Apache Traffic Server Security Team.

You can read more about the security policy on:

Advisories

This section is experimental: it provides advisories since 2023 and may lag behind the official CVE publications. It may also lack details found on the project security pages linked above. If you have any feedback on how you would like this data to be provided, you are welcome to reach out on our public mailinglist or privately on security@apache.org

HTTP/2 multiplexed origin sessions are reused without certificate re-verification

CVE-2026-65325 [CVE] [CVE json] [OSV json]

Last updated: 2026-07-29T08:23:24.104Z

Affected

  • Apache Traffic Server from 9.0.0 through 9.2.14
  • Apache Traffic Server from 10.0.0 through 10.1.3

Description

Apache Traffic Server reuses multiplexed HTTP/2 origin connections without verifying the server certificate covers the new request hostname.

This issue affects Apache Traffic Server: from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3.

Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.

References

Credits

  • Apache Community (reporter)
  • Omkhar Arasaratnam (reporter)

HTTP/2 and HTTP/3 dechunking removes per-stream buffer cap, allowing memory exhaustion

CVE-2026-65324 [CVE] [CVE json] [OSV json]

Last updated: 2026-07-29T08:17:42.240Z

Affected

  • Apache Traffic Server from 8.0.0 through 8.1.9
  • Apache Traffic Server from 9.0.0 through 9.2.14
  • Apache Traffic Server from 10.0.0 through 10.1.3

Description

Apache Traffic Server drops the per-stream buffer cap when dechunking HTTP/2 or HTTP/3 responses, letting a slow client exhaust server memory.

This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3.

Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.

References

Credits

  • Apache Community (reporter)
  • Omkhar Arasaratnam (reporter)

HPACK encoder desynchronizes from the decoder after a failed header encode

CVE-2026-65100 [CVE] [CVE json] [OSV json]

Last updated: 2026-07-29T09:06:12.502Z

Affected

  • Apache Traffic Server from 8.0.0 through 8.1.9
  • Apache Traffic Server from 9.0.0 through 9.2.14
  • Apache Traffic Server from 10.0.0 through 10.1.3

Description

Apache Traffic Server updates the HTTP/2 HPACK dynamic table before confirming the header block encoded successfully, so an encode failure leaves the encoder out of sync with the peer decoder and corrupts subsequent header blocks on the connection.

This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3.

Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.

References

Credits

  • Omkhar Arasaratnam (reporter)
  • Apache Community (reporter)

DoS vulnerability in HTTP/2 via stalled flow-control conditions

CVE-2026-59173 [CVE] [CVE json] [OSV json]

Last updated: 2026-07-18T12:52:08.684Z

Affected

  • Apache Traffic Server from 9.0.0 through 9.2.13
  • Apache Traffic Server from 10.0.0 through 10.1.2

Description

Uncontrolled Resource Consumption vulnerability in Apache Traffic Server.

This issue affects Apache Traffic Server: from 9.0.0 through 9.1.13, from 10.0.0 through 10.1.2.

Users are recommended to upgrade to version 9.1.14 or 10.1.3, which fixes the issue.

References

Credits

  • Okta Red Team (reporter)

Plugins resetting the redirect counter enable SSRF amplification

CVE-2026-58189 [CVE] [CVE json] [OSV json]

Last updated: 2026-07-29T09:05:13.041Z

Affected

  • Apache Traffic Server from 8.0.0 through 8.1.9
  • Apache Traffic Server from 9.0.0 through 9.2.14
  • Apache Traffic Server from 10.0.0 through 10.1.3

Description

Apache Traffic Server allows redirect-limit bypass when plugins reset the retry counter, enabling SSRF amplification.

This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3.

Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.

References

Credits

  • Omkhar Arasaratnam (reporter)

Memory-safety and limit-bypass errors across experimental plugins

CVE-2026-58188 [CVE] [CVE json] [OSV json]

Last updated: 2026-07-29T09:04:20.085Z

Affected

  • Apache Traffic Server from 8.0.0 through 8.1.9
  • Apache Traffic Server from 9.0.0 through 9.2.14
  • Apache Traffic Server from 10.0.0 through 10.1.3

Description

Several Apache Traffic Server experimental plugins have memory-safety and limit-bypass errors.

This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3.

Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.

References

Credits

  • Yon Harlicaj (reporter)
  • Apache Community (reporter)
  • Omkhar Arasaratnam (reporter)

Multiplexer plugin chunk decoder enables a denial of service

CVE-2026-58187 [CVE] [CVE json] [OSV json]

Last updated: 2026-07-29T09:03:17.157Z

Affected

  • Apache Traffic Server from 8.0.0 through 8.1.9
  • Apache Traffic Server from 9.0.0 through 9.2.14
  • Apache Traffic Server from 10.0.0 through 10.1.3

Description

The Apache Traffic Server multiplexer plugin overruns its chunk-decode buffer on upstream input, enabling denial of service.

This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3.

Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.

References

Credits

  • Omkhar Arasaratnam (reporter)

webp_transform plugin decodes unsafely and mislabels degraded responses

CVE-2026-58186 [CVE] [CVE json] [OSV json]

Last updated: 2026-07-29T09:01:35.556Z

Affected

  • Apache Traffic Server from 8.0.0 through 8.1.9
  • Apache Traffic Server from 9.0.0 through 9.2.14
  • Apache Traffic Server from 10.0.0 through 10.1.3

Description

The Apache Traffic Server webp_transform plugin can decode unsafely and serve mislabeled, cacheable responses.

This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3.

Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.

References

Credits

  • Omkhar Arasaratnam (reporter)

Use-after-free in the intercept plugin

CVE-2026-58185 [CVE] [CVE json] [OSV json]

Last updated: 2026-07-29T08:57:42.562Z

Affected

  • Apache Traffic Server from 8.0.0 through 8.1.9
  • Apache Traffic Server from 9.0.0 through 9.2.14
  • Apache Traffic Server from 10.0.0 through 10.1.3

Description

The Apache Traffic Server intercept plugin has a use-after-free.

This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3.

Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.

References

Credits

  • Omkhar Arasaratnam (reporter)

header_rewrite plugin cookie handling can corrupt memory

CVE-2026-58184 [CVE] [CVE json] [OSV json]

Last updated: 2026-07-29T08:56:45.008Z

Affected

  • Apache Traffic Server from 8.0.0 through 8.1.9
  • Apache Traffic Server from 9.0.0 through 9.2.14
  • Apache Traffic Server from 10.0.0 through 10.1.3

Description

The Apache Traffic Server header_rewrite plugin can crash or corrupt memory during cookie operations and CIDR condition matching.

This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3.

Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.

References

Credits

  • Omkhar Arasaratnam (reporter)

prefetch plugin can crash on attacker-influenced input

CVE-2026-58183 [CVE] [CVE json] [OSV json]

Last updated: 2026-07-29T08:55:45.403Z

Affected

  • Apache Traffic Server from 8.0.0 through 8.1.9
  • Apache Traffic Server from 9.0.0 through 9.2.14
  • Apache Traffic Server from 10.0.0 through 10.1.3

Description

The Apache Traffic Server prefetch plugin can crash when processing attacker-influenced input.

This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3.

Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.

References

Credits

  • Omkhar Arasaratnam (reporter)

ts_lua plugin has initialization and resource-handling errors

CVE-2026-58182 [CVE] [CVE json] [OSV json]

Last updated: 2026-07-29T08:54:41.470Z

Affected

  • Apache Traffic Server from 8.0.0 through 8.1.9
  • Apache Traffic Server from 9.0.0 through 9.2.14
  • Apache Traffic Server from 10.0.0 through 10.1.3

Description

The Apache Traffic Server ts_lua plugin mishandles initialization, transform context, and per-instance state.

This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3.

Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.

References

Credits

  • Omkhar Arasaratnam (reporter)

uri_signing and url_sig plugins can exhaust the stack or crash

CVE-2026-58181 [CVE] [CVE json] [OSV json]

Last updated: 2026-07-29T08:46:00.299Z

Affected

  • Apache Traffic Server from 8.0.0 through 8.1.9
  • Apache Traffic Server from 9.0.0 through 9.2.14
  • Apache Traffic Server from 10.0.0 through 10.1.3

Description

The Apache Traffic Server uri_signing and url_sig plugins can exhaust the stack or crash on attacker input.

This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3.

Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.

References

Credits

  • Apache Community (reporter)
  • Omkhar Arasaratnam (reporter)

txn_box plugin overflows the stack from attacker input

CVE-2026-58180 [CVE] [CVE json] [OSV json]

Last updated: 2026-07-29T08:45:10.821Z

Affected

  • Apache Traffic Server from 8.0.0 through 8.1.9
  • Apache Traffic Server from 9.0.0 through 9.2.14
  • Apache Traffic Server from 10.0.0 through 10.1.3

Description

The Apache Traffic Server txn_box plugin overflows the stack from attacker-controlled input.

This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3.

Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.

References

Credits

  • Apache Community (reporter)

regex_remap plugin overflows the stack from attacker input

CVE-2026-58179 [CVE] [CVE json] [OSV json]

Last updated: 2026-07-29T08:44:28.901Z

Affected

  • Apache Traffic Server from 8.0.0 through 8.1.9
  • Apache Traffic Server from 9.0.0 through 9.2.14
  • Apache Traffic Server from 10.0.0 through 10.1.3

Description

The Apache Traffic Server regex_remap plugin overflows the stack and integers from substitution input.

This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3.

Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.

References

Credits

  • Apache Community (reporter)

ESI plugin allows uncontrolled recursion and server-side request forgery

CVE-2026-58178 [CVE] [CVE json] [OSV json]

Last updated: 2026-07-29T08:43:21.506Z

Affected

  • Apache Traffic Server from 8.0.0 through 8.1.9
  • Apache Traffic Server from 9.0.0 through 9.2.14
  • Apache Traffic Server from 10.0.0 through 10.1.3

Description

The Apache Traffic Server ESI plugin can recurse without bound and fetch attacker-controlled URLs.

This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3.

Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.

References

Credits

  • Apache Community (reporter)

Memory-safety and path-traversal errors in the Cripts framework

CVE-2026-58177 [CVE] [CVE json] [OSV json]

Last updated: 2026-07-29T08:42:36.014Z

Affected

  • Apache Traffic Server from 10.0.0 through 10.1.3

Description

The Apache Traffic Server Cripts framework has out-of-bounds writes, path traversal, and use-after-free errors.

This issue affects Apache Traffic Server: from 10.0.0 through 10.1.3.

Users are recommended to upgrade to version 10.1.4, which fix the issue.

References

Credits

  • Apache Community (reporter)
  • Omkhar Arasaratnam (reporter)

HostDB SRV handling leaks memory

CVE-2026-58175 [CVE] [CVE json] [OSV json]

Last updated: 2026-07-29T08:41:45.146Z

Affected

  • Apache Traffic Server from 8.0.0 through 8.1.9
  • Apache Traffic Server from 9.0.0 through 9.2.14
  • Apache Traffic Server from 10.0.0 through 10.1.3

Description

Apache Traffic Server leaks memory when handling HostDB SRV records.

This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3.

Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.

References

Credits

  • Omkhar Arasaratnam (reporter)

Remap configuration lifetime and TOCTOU errors cause use-after-free

CVE-2026-58164 [CVE] [CVE json] [OSV json]

Last updated: 2026-07-29T08:37:38.531Z

Affected

  • Apache Traffic Server from 8.0.0 through 8.1.9
  • Apache Traffic Server from 9.0.0 through 9.2.14
  • Apache Traffic Server from 10.0.0 through 10.1.3

Description

Apache Traffic Server has use-after-free and time-of-check/time-of-use errors in remap configuration handling.

This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3.

Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.

References

Credits

  • Apache Community (reporter)
  • Omkhar Arasaratnam (reporter)

Cache deserialization and lifetime errors can corrupt state or crash the server

CVE-2026-58163 [CVE] [CVE json] [OSV json]

Last updated: 2026-07-29T08:36:53.072Z

Affected

  • Apache Traffic Server from 8.0.0 through 8.1.9
  • Apache Traffic Server from 9.0.0 through 9.2.14
  • Apache Traffic Server from 10.0.0 through 10.1.3

Description

Apache Traffic Server mishandles on-disk cache fields and object lifetimes, corrupting state or crashing.

This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3.

Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.

References

Credits

  • Apache Community (reporter)
  • Omkhar Arasaratnam (reporter)

Certifier plugin trusts client SNI when generating certificates

CVE-2026-58162 [CVE] [CVE json] [OSV json]

Last updated: 2026-07-29T08:36:12.596Z

Affected

  • Apache Traffic Server from 8.0.0 through 8.1.9
  • Apache Traffic Server from 9.0.0 through 9.2.14
  • Apache Traffic Server from 10.0.0 through 10.1.3

Description

The Apache Traffic Server certifier plugin generates certificates based on attacker-controlled client SNI.

This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3.

Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.

References

Credits

  • Omkhar Arasaratnam (reporter)

Memory-safety errors in TLS and SNI handling can crash the server

CVE-2026-58161 [CVE] [CVE json] [OSV json]

Last updated: 2026-07-29T08:35:35.583Z

Affected

  • Apache Traffic Server from 8.0.0 through 8.1.9
  • Apache Traffic Server from 9.0.0 through 9.2.14
  • Apache Traffic Server from 10.0.0 through 10.1.3

Description

Apache Traffic Server can crash from null dereferences and dangling references in TLS and SNI handling.

This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3.

Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.

References

Credits

  • Omkhar Arasaratnam (reporter)

Out-of-bounds reads while parsing DNS responses

CVE-2026-58160 [CVE] [CVE json] [OSV json]

Last updated: 2026-07-29T08:34:31.111Z

Affected

  • Apache Traffic Server from 8.0.0 through 8.1.9
  • Apache Traffic Server from 9.0.0 through 9.2.14
  • Apache Traffic Server from 10.0.0 through 10.1.3

Description

Apache Traffic Server reads out of bounds while parsing DNS answers.

This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3.

Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.

References

Credits

  • Apache Community (reporter)
  • Omkhar Arasaratnam (reporter)

Listener and ACL handling allow access-control bypass

CVE-2026-58159 [CVE] [CVE json] [OSV json]

Last updated: 2026-07-29T08:31:14.552Z

Affected

  • Apache Traffic Server from 8.0.0 through 8.1.9
  • Apache Traffic Server from 9.0.0 through 9.2.14
  • Apache Traffic Server from 10.0.0 through 10.1.3

Description

Apache Traffic Server can bypass IP access controls on UDS listeners and through ACL matching errors.

This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3.

Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.

References

Credits

  • Apache Community (reporter)
  • Omkhar Arasaratnam (reporter)

PROXY protocol parsing has port truncation and a stack overflow

CVE-2026-58158 [CVE] [CVE json] [OSV json]

Last updated: 2026-07-29T08:26:27.296Z

Affected

  • Apache Traffic Server from 8.0.0 through 8.1.9
  • Apache Traffic Server from 9.0.0 through 9.2.14
  • Apache Traffic Server from 10.0.0 through 10.1.3

Description

Apache Traffic Server mishandles PROXY protocol input, truncating ports and overflowing the stack.

This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3.

Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.

References

Credits

  • Apache Community (reporter)

Improper server-session reuse can expose data across client connections

CVE-2026-58157 [CVE] [CVE json] [OSV json]

Last updated: 2026-07-29T08:25:47.725Z

Affected

  • Apache Traffic Server from 8.0.0 through 8.1.9
  • Apache Traffic Server from 9.0.0 through 9.2.14
  • Apache Traffic Server from 10.0.0 through 10.1.3

Description

Apache Traffic Server can reuse server sessions and tunnels improperly, exposing data across client connections.

This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3.

Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.

References

Credits

  • Apache Community (reporter)
  • Omkhar Arasaratnam (reporter)

URL and port parsing errors allow access-control bypass

CVE-2026-58156 [CVE] [CVE json] [OSV json]

Last updated: 2026-07-29T08:25:07.986Z

Affected

  • Apache Traffic Server from 8.0.0 through 8.1.9
  • Apache Traffic Server from 9.0.0 through 9.2.14
  • Apache Traffic Server from 10.0.0 through 10.1.3

Description

Apache Traffic Server mis-parses ports in URLs and userinfo, allowing port-based access-control bypass.

This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3.

Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.

References

Credits

  • Apache Community (reporter)
  • Omkhar Arasaratnam (reporter)

Header-name length truncation enables header aliasing and request smuggling

CVE-2026-58155 [CVE] [CVE json] [OSV json]

Last updated: 2026-07-29T08:24:30.308Z

Affected

  • Apache Traffic Server from 8.0.0 through 8.1.9
  • Apache Traffic Server from 9.0.0 through 9.2.14
  • Apache Traffic Server from 10.0.0 through 10.1.3

Description

Apache Traffic Server truncates over-long header names, allowing header aliasing, request smuggling, and policy bypass.

This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3.

Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.

References

Credits

  • Omkhar Arasaratnam (reporter)

Memory-safety errors in MIME and header parsing

CVE-2026-58154 [CVE] [CVE json] [OSV json]

Last updated: 2026-07-29T08:23:57.475Z

Affected

  • Apache Traffic Server from 8.0.0 through 8.1.9
  • Apache Traffic Server from 9.0.0 through 9.2.14
  • Apache Traffic Server from 10.0.0 through 10.1.3

Description

Apache Traffic Server can write out of bounds or overflow integers while parsing MIME and HTTP headers.

This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3.

Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.

References

Credits

  • Michael Bommarito (reporter)
  • Apache Community (reporter)
  • Omkhar Arasaratnam (reporter)

HTTP/2 to HTTP/1 conversion forwards origin trailers to clients unsafely

CVE-2026-58153 [CVE] [CVE json] [OSV json]

Last updated: 2026-07-29T08:17:07.259Z

Affected

  • Apache Traffic Server from 10.0.0 through 10.1.3

Description

Apache Traffic Server forwards HTTP/2 origin trailers to HTTP/1 clients without proper chunked framing when converting HTTP/2 to HTTP/1.

This issue affects Apache Traffic Server: from 10.0.0 through 10.1.3.

Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.

References

Credits

  • Apache Community (reporter)
  • Omkhar Arasaratnam (reporter)

Integer-handling errors in HPACK/XPACK decoding corrupt memory

CVE-2026-58152 [CVE] [CVE json] [OSV json]

Last updated: 2026-07-29T08:16:17.147Z

Affected

  • Apache Traffic Server from 8.0.0 through 8.1.9
  • Apache Traffic Server from 9.0.0 through 9.2.14
  • Apache Traffic Server from 10.0.0 through 10.1.3

Description

Apache Traffic Server mishandles integers while decoding HPACK/XPACK headers, corrupting memory.

This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3.

Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.

References

Credits

  • Apache Community (reporter)
  • Javid Khan (reporter)

Abusive HTTP/2 framing can exhaust resources and crash the server

CVE-2026-58151 [CVE] [CVE json] [OSV json]

Last updated: 2026-07-29T08:15:41.513Z

Affected

  • Apache Traffic Server from 8.0.0 through 8.1.9
  • Apache Traffic Server from 9.0.0 through 9.2.14
  • Apache Traffic Server from 10.0.0 through 10.1.3

Description

Apache Traffic Server can be crashed or driven to resource exhaustion by abusive HTTP/2 framing and flow-control.

This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3.

Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.

References

Credits

  • Apache Community (reporter)
  • Omkhar Arasaratnam (reporter)

HTTP/2 requests with Transfer-Encoding are not rejected, allowing request smuggling

CVE-2026-58150 [CVE] [CVE json] [OSV json]

Last updated: 2026-07-29T07:30:24.423Z

Affected

  • Apache Traffic Server from 8.0.0 through 8.1.9
  • Apache Traffic Server from 9.0.0 through 9.2.14
  • Apache Traffic Server from 10.0.0 through 10.1.3

Description

Apache Traffic Server does not reject Transfer-Encoding in HTTP/2 requests, allowing downgrade request smuggling.

This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3.

Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.

References

Credits

  • Apache Community (reporter)

Malformed chunked message body allows request smuggling

CVE-2026-57834 [CVE] [CVE json] [OSV json]

Last updated: 2026-07-29T07:25:43.006Z

Affected

  • Apache Traffic Server from 8.0.0 through 8.1.9
  • Apache Traffic Server from 9.0.0 through 9.2.14
  • Apache Traffic Server from 10.0.0 through 10.1.3

Description

Apache Traffic Server allows request smuggling if chunked messages are malformed.

This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3.

Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.

References

Credits

  • Haruki Oyama (reporter)
  • Katsutoshi Ikenoya (LY Corporation) (reporter)
  • Apache Community (reporter)

SNI to Host header matching policy is not properly enforced

CVE-2026-41920 [CVE] [CVE json] [OSV json]

Last updated: 2026-07-29T07:17:57.749Z

Affected

  • Apache Traffic Server from 9.0.0 through 9.1.14
  • Apache Traffic Server from 10.0.0 through 10.1.3

Description

Improper Access Control vulnerability in Apache Traffic Server.

This issue affects Apache Traffic Server: from 9.0.0 through 9.1.14, from 10.0.0 through 10.1.3.

Users are recommended to upgrade to version 9.1.15 or 10.1.4, which fixes the issue.

References

Credits

  • JD Marsters (Bhut Red) (reporter)
  • Apache Community (reporter)

Buffer overflow via Host field that has a long string value

CVE-2026-33930 [CVE] [CVE json] [OSV json]

Last updated: 2026-07-29T07:23:50.719Z

Affected

  • Apache Traffic Server from 8.0.0 through 8.1.9
  • Apache Traffic Server from 9.0.0 through 9.2.14
  • Apache Traffic Server from 10.0.0 through 10.1.3

Description

Apache Traffic Server copies the client Host header into a fixed-size stack buffer without a bound during redirect handling, so an over-long Host header overflows the stack when redirect following is enabled.

This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3.

Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.

References

Credits

  • Pengpeng Hou (reporter)

Untrusted @ headers can spoof ATS internal metadata

CVE-2026-33267 [CVE] [CVE json] [OSV json]

Last updated: 2026-07-29T07:21:47.559Z

Affected

  • Apache Traffic Server from 9.2.0 through 9.2.14
  • Apache Traffic Server from 10.1.0 through 10.1.3

Description

Improper Input Validation vulnerability in Apache Traffic Server.

This issue affects Apache Traffic Server: from 9.2.0 through 9.2.14, from 10.1.0 through 10.1.3.

Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fixes the issue.

References

Credits

  • Charlie Campbell (reporter)
  • Apache Community (reporter)

Request smuggling via chunked extension quoted-string parsing

CVE-2026-24033 [CVE] [CVE json] [OSV json]

Last updated: 2026-07-29T07:22:37.470Z

Affected

  • Apache Traffic Server from 10.0.0 through 10.1.3
  • Apache Traffic Server from 9.0.0 through 9.2.14

Description

Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') vulnerability in Apache Traffic Server.

This issue affects Apache Traffic Server: from 10.0.0 through 10.1.3, from 9.0.0 through 9.2.14.

Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fixes the issue.

References

Credits

  • Rajat Raghav (reporter)
  • Katsutoshi Ikenoya (LY Corporation) (reporter)

Regex mappings match with malicious domain names

CVE-2026-22068 [CVE] [CVE json] [OSV json]

Last updated: 2026-07-29T07:18:58.921Z

Affected

  • Apache Traffic Server from 10.0.x through 10.1.3
  • Apache Traffic Server from 9.0.x through 9.2.14

Description

Regular Expression without Anchors vulnerability in Apache Traffic Server.

This issue affects Apache Traffic Server: from 10.0.X through 10.1.3, from 9.0.X through 9.2.14.

Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fixes the issue.

References

Credits

  • Omkhar Arasaratnam (reporter)
  • Apache Community (reporter)

Malformed chunked message body allows request smuggling

CVE-2025-65114 [CVE] [CVE json] [OSV json]

Last updated: 2026-04-10T15:56:14.648Z

Affected

  • Apache Traffic Server from 9.0.0 through 9.2.12
  • Apache Traffic Server from 10.0.0 through 10.1.1

Description

Apache Traffic Server allows request smuggling if chunked messages are malformed. 

This issue affects Apache Traffic Server: from 9.0.0 through 9.2.12, from 10.0.0 through 10.1.1.

Users are recommended to upgrade to version 9.2.13 or 10.1.2, which fix the issue.

References

Credits

  • Katsutoshi Ikenoya (reporter)

A simple legitimate POST request causes a crash

CVE-2025-58136 [CVE] [CVE json] [OSV json]

Last updated: 2026-04-10T15:53:47.491Z

Affected

  • Apache Traffic Server from 10.0.0 through 10.1.1
  • Apache Traffic Server from 9.0.0 through 9.2.12

Description

A bug in POST request handling causes a crash under a certain condition.

This issue affects Apache Traffic Server: from 10.0.0 through 10.1.1, from 9.0.0 through 9.2.12.

Users are recommended to upgrade to version 10.1.2 or 9.2.13, which fix the issue.

A workaround for older versions is to set proxy.config.http.request_buffer_enabled to 0 (the default value is 0). 

References

Remote DoS via memory exhaustion in ESI Plugin

CVE-2025-49763 [CVE] [CVE json] [OSV json]

Last updated: 2025-06-19T10:07:13.563Z

Affected

  • Apache Traffic Server from 10.0.0 through 10.0.5
  • Apache Traffic Server from 9.0.0 through 9.2.10

Description

ESI plugin does not have the limit for maximum inclusion depth, and that allows excessive memory consumption if malicious instructions are inserted.

Users can use a new setting for the plugin (--max-inclusion-depth) to limit it.

This issue affects Apache Traffic Server: from 10.0.0 through 10.0.5, from 9.0.0 through 9.2.10.

Users are recommended to upgrade to version 9.2.11 or 10.0.6, which fixes the issue.

References

Credits

  • Yohann Sillam (reporter)

Client IP address from PROXY protocol is not used for ACL

CVE-2025-31698 [CVE] [CVE json] [OSV json]

Last updated: 2025-06-19T10:07:45.344Z

Affected

  • Apache Traffic Server from 10.0.0 through 10.0.6
  • Apache Traffic Server from 9.0.0 through 9.2.10

Description

ACL configured in ip_allow.config or remap.config does not use IP addresses that are provided by PROXY protocol.

Users can use a new setting (proxy.config.acl.subjects) to choose which IP addresses to use for the ACL if Apache Traffic Server is configured to accept PROXY protocol. 

This issue affects undefined: from 10.0.0 through 10.0.6, from 9.0.0 through 9.2.10.

Users are recommended to upgrade to version 9.2.11 or 10.0.6, which fixes the issue.

References

Expect header field can unreasonably retain resource

CVE-2024-56202 [CVE] [CVE json] [OSV json]

Last updated: 2025-03-06T11:09:09.771Z

Affected

  • Apache Traffic Server from 9.0.0 through 9.2.8
  • Apache Traffic Server from 10.0.0 through 10.0.3

Description

Expected Behavior Violation vulnerability in Apache Traffic Server.

This issue affects Apache Traffic Server: from 9.0.0 through 9.2.8, from 10.0.0 through 10.0.3.

Users are recommended to upgrade to versions 9.2.9 or 10.0.4 or newer, which fixes the issue.

References

Credits

  • David Carlin (reporter)

ACL is not fully compatible with older versions

CVE-2024-56196 [CVE] [CVE json] [OSV json]

Last updated: 2025-03-06T11:21:46.767Z

Affected

  • Apache Traffic Server from 10.0.0 through 10.0.3

Description

Improper Access Control vulnerability in Apache Traffic Server.

This issue affects Apache Traffic Server: from 10.0.0 through 10.0.3.

Users are recommended to upgrade to version 10.0.4, which fixes the issue.

References

Credits

  • Chris McFarlen (reporter)

Intercept plugins are not access controlled

CVE-2024-56195 [CVE] [CVE json] [OSV json]

Last updated: 2025-03-06T11:23:34.892Z

Affected

  • Apache Traffic Server from 9.2.0 through 9.2.8
  • Apache Traffic Server from 10.0.0 through 10.0.3

Description

Improper Access Control vulnerability in Apache Traffic Server.

This issue affects Apache Traffic Server: from 9.2.0 through 9.2.8, from 10.0.0 through 10.0.3.

Users are recommended to upgrade to version 9.2.9 or 10.0.4, which fixes the issue.

References

Credits

  • Masaori Koshiba (reporter)

Malformed chunked message body allows request smuggling

CVE-2024-53868 [CVE] [CVE json] [OSV json]

Last updated: 2025-04-03T08:58:55.409Z

Affected

  • Apache Traffic Server from 9.2.0 through 9.2.9
  • Apache Traffic Server from 10.0.0 through 10.0.4

Description

Apache Traffic Server allows request smuggling if chunked messages are malformed. 

This issue affects Apache Traffic Server: from 9.2.0 through 9.2.9, from 10.0.0 through 10.0.4.

Users are recommended to upgrade to version 9.2.10 or 10.0.5, which fixes the issue.

References

Credits

  • Jeppe Bonde Weikop (reporter)

Server process can fail to drop privilege

CVE-2024-50306 [CVE] [CVE json] [OSV json]

Last updated: 2024-11-14T09:55:41.120Z

Affected

  • Apache Traffic Server from 9.2.0 through 9.2.5
  • Apache Traffic Server from 10.0.0 through 10.0.1

Description

Unchecked return value can allow Apache Traffic Server to retain privileges on startup.

This issue affects Apache Traffic Server: from 9.2.0 through 9.2.5, from 10.0.0 through 10.0.1.

Users are recommended to upgrade to version 9.2.6 or 10.0.2, which fixes the issue.

References

Credits

  • Jeffrey BENCTEUX (reporter)

Valid Host field value can cause crashes

CVE-2024-50305 [CVE] [CVE json] [OSV json]

Last updated: 2024-11-14T09:54:18.691Z

Affected

  • Apache Traffic Server from 9.2.0 through 9.2.5

Description

Valid Host header field can cause Apache Traffic Server to crash on some platforms.

This issue affects Apache Traffic Server: from 9.2.0 through 9.2.5.

Users are recommended to upgrade to version 9.2.6, which fixes the issue, or 10.0.2, which does not have the issue.

References

Cache key plugin is vulnerable to cache poisoning attack

CVE-2024-38479 [CVE] [CVE json] [OSV json]

Last updated: 2024-12-19T08:48:33.164Z

Affected

  • Apache Traffic Server from 8.0.0 through 8.1.11
  • Apache Traffic Server from 9.0.0 through 9.2.5

Description

Improper Input Validation vulnerability in Apache Traffic Server.

This issue affects Apache Traffic Server: from 8.0.0 through 8.1.11, from 9.0.0 through 9.2.5.

Users are recommended to upgrade to version 9.2.6, which fixes the issue, or 10.0.2, which does not have the issue.

References

Request smuggling via pipelining after a chunked message body

CVE-2024-38311 [CVE] [CVE json] [OSV json]

Last updated: 2025-03-06T11:34:14.593Z

Affected

  • Apache Traffic Server from 8.0.0 through 8.1.11
  • Apache Traffic Server from 9.0.0 through 9.2.8
  • Apache Traffic Server from 10.0.0 through 10.0.3

Description

Improper Input Validation vulnerability in Apache Traffic Server.

This issue affects Apache Traffic Server: from 8.0.0 through 8.1.11, from 9.0.0 through 9.2.8, from 10.0.0 through 10.0.3.

Users are recommended to upgrade to version 9.2.9 or 10.0.4, which fixes the issue.

References

Credits

  • Ben Kallus (reporter)

Invalid Accept-Encoding can force forwarding requests

CVE-2024-35296 [CVE] [CVE json] [OSV json]

Last updated: 2024-07-26T09:11:09.740Z

Affected

  • Apache Traffic Server from 8.0.0 through 8.1.10
  • Apache Traffic Server from 9.0.0 through 9.2.4

Description

Invalid Accept-Encoding header can cause Apache Traffic Server to fail cache lookup and force forwarding requests.

This issue affects Apache Traffic Server: from 8.0.0 through 8.1.10, from 9.0.0 through 9.2.4.

Users are recommended to upgrade to version 8.1.11 or 9.2.5, which fixes the issue.

References

Credits

  • Min Chen (reporter)

Incomplete check for chunked trailer section allows request smuggling

CVE-2024-35161 [CVE] [CVE json] [OSV json]

Last updated: 2024-08-13T08:48:31.440Z

Affected

  • Apache Traffic Server from 8.0.0 through 8.1.10
  • Apache Traffic Server from 9.0.0 through 9.2.4

Description

Apache Traffic Server forwards malformed HTTP chunked trailer section to origin servers. This can be utilized for request smuggling and may also lead cache poisoning if the origin servers are vulnerable.

This issue affects Apache Traffic Server: from 8.0.0 through 8.1.10, from 9.0.0 through 9.2.4.

Users can set a new setting (proxy.config.http.drop_chunked_trailers) not to forward chunked trailer section.

Users are recommended to upgrade to version 8.1.11 or 9.2.5, which fixes the issue.

References

Credits

  • Keran Mu (reporter)

HTTP/2 CONTINUATION frames can be utilized for DoS attack

CVE-2024-31309 [CVE] [CVE json] [OSV json]

Last updated: 2024-04-10T15:16:21.844Z

Affected

  • Apache Traffic Server from 8.0.0 through 8.1.9
  • Apache Traffic Server from 9.0.0 through 9.2.3

Description

HTTP/2 CONTINUATION DoS attack can cause Apache Traffic Server to consume more resources on the server.  Version from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.3 are affected.

Users can set a new setting (proxy.config.http2.max_continuation_frames_per_minute) to limit the number of CONTINUATION frames per minute.  ATS does have a fixed amount of memory a request can use and ATS adheres to these limits in previous releases.

Users are recommended to upgrade to versions 8.1.10 or 9.2.4 which fixes the issue.

References

Credits

  • Bartek Nowotarski (reporter)

s3_auth plugin problem with hash calculation

CVE-2023-41752 [CVE] [CVE json] [OSV json]

Last updated: 2023-10-17T06:57:44.046Z

Affected

  • Apache Traffic Server from 8.0.0 through 8.1.8
  • Apache Traffic Server from 9.0.0 through 9.2.2

Description

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Traffic Server.

This issue affects Apache Traffic Server: from 8.0.0 through 8.1.8, from 9.0.0 through 9.2.2.

Users are recommended to upgrade to version 8.1.9 or 9.2.3, which fixes the issue.

References

Credits

  • Masakazu Kitajo (finder)

Malformed http/2 frames can cause an abort

CVE-2023-39456 [CVE] [CVE json] [OSV json]

Last updated: 2023-10-17T06:58:15.367Z

Affected

  • Apache Traffic Server from 9.0.0 through 9.2.2

Description

Improper Input Validation vulnerability in Apache Traffic Server with malformed HTTP/2 frames.

This issue affects Apache Traffic Server: from 9.0.0 through 9.2.2.

Users are recommended to upgrade to version 9.2.3, which fixes the issue.

References

Credits

  • Akshat Parikh (finder)

Incomplete field name check allows request smuggling

CVE-2023-38522 [CVE] [CVE json] [OSV json]

Last updated: 2024-08-13T08:46:41.192Z

Affected

  • Apache Traffic Server from 8.0.0 through 8.1.10
  • Apache Traffic Server from 9.0.0 through 9.2.4

Description

Apache Traffic Server accepts characters that are not allowed for HTTP field names and forwards malformed requests to origin servers. This can be utilized for request smuggling and may also lead cache poisoning if the origin servers are vulnerable.

This issue affects Apache Traffic Server: from 8.0.0 through 8.1.10, from 9.0.0 through 9.2.4.

Users are recommended to upgrade to version 8.1.11 or 9.2.5, which fixes the issue.

References

Credits

  • Ben Kallus (finder)

Differential fuzzing for HTTP request parsing discrepancies

CVE-2023-33934 [CVE] [CVE json]

Last updated: 2023-09-28T08:24:06.964Z

Affected

  • Apache Traffic Server through 9.2.1

Description

Improper Input Validation vulnerability in Apache Software Foundation Apache Traffic Server.

This issue affects Apache Traffic Server: through 9.2.1.

References

Credits

  • Bahruz Jabiyev, Anthony Gavazzi, Engin Kirda, Kaan Onarlioglu, Adi Peleg, Harvey Tuch (finder)

s3_auth plugin problem with hash calculation

CVE-2023-33933 [CVE] [CVE json] [OSV json]

Last updated: 2023-08-31T19:49:23.749Z

Affected

  • Apache Traffic Server from 8.0.0 through 9.2.0

Description

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Software Foundation Apache Traffic Server.

This issue affects Apache Traffic Server: from 8.0.0 through 9.2.0.

8.x users should upgrade to 8.1.7 or later versions
9.x users should upgrade to 9.2.1 or later versions

References

Credits

  • Masakazu Kitajo (reporter)

Configuration option to block the PUSH method in ATS didn’t work

CVE-2023-30631 [CVE] [CVE json] [OSV json]

Last updated: 2023-06-14T07:44:52.725Z

Affected

  • Apache Traffic Server from 8.0.0 through 9.2.0

Description

Improper Input Validation vulnerability in Apache Software Foundation Apache Traffic Server.  The configuration option proxy.config.http.push_method_enabled didn’t function.  However, by default the PUSH method is blocked in the ip_allow configuration file.

This issue affects Apache Traffic Server: from 8.0.0 through 9.2.0.

8.x users should upgrade to 8.1.7 or later versions
9.x users should upgrade to 9.2.1 or later versions

References

Credits

  • Chris Lemmons (finder)

Invalid Range header causes a crash

CVE-2022-47185 [CVE] [CVE json] [OSV json]

Last updated: 2023-08-09T06:57:36.707Z

Affected

  • Apache Traffic Server through 9.2.1

Description

Improper input validation vulnerability on the range header in Apache Software Foundation Apache Traffic Server.

This issue affects Apache Traffic Server: through 9.2.1.

References

Credits

  • Katsutoshi Ikenoya (finder)

The TRACE method can be use to disclose network information

CVE-2022-47184 [CVE] [CVE json] [OSV json]

Last updated: 2023-06-14T07:42:29.792Z

Affected

  • Apache Traffic Server from 8.0.0 through 9.2.0

Description

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Software Foundation Apache Traffic Server.

This issue affects Apache Traffic Server: 8.0.0 to 9.2.0.

References

Credits

  • Martin O’Neal (reporter)

Security issues with the xdebug plugin

CVE-2022-40743 [CVE] [CVE json] [OSV json]

Last updated: 2023-07-17T14:33:07.403Z

Affected

  • Apache Traffic Server from 9.0.0 through 9.1.3

Description

Improper Input Validation vulnerability for the xdebug plugin in Apache Software Foundation Apache Traffic Server can lead to cross site scripting and cache poisoning attacks.

This issue affects Apache Traffic Server: 9.0.0 to 9.1.3. Users should upgrade to 9.1.4 or later versions.

References

Credits

  • Nick Frost (finder)

Improperly reading the client requests

CVE-2022-37392 [CVE] [CVE json] [OSV json]

Last updated: 2022-12-19T10:58:23.000Z

Affected

  • Apache Traffic Server from 8.0.0 through 9.1.3

Description

Improper Check for Unusual or Exceptional Conditions vulnerability in handling the requests to Apache Traffic Server. This issue affects Apache Traffic Server 8.0.0 to 9.1.2.

References

Credits

  • Menno de Gier (finder)

Improperly handled requests can cause crashes in specific plugins

CVE-2022-32749 [CVE] [CVE json] [OSV json]

Last updated: 2022-12-19T10:51:20.718Z

Affected

  • Apache Traffic Server from 8.0.0 through 9.1.3

Description

Improper Check for Unusual or Exceptional Conditions vulnerability handling requests in Apache Traffic Server allows an attacker to crash the server under certain conditions.

This issue affects Apache Traffic Server: from 8.0.0 through 9.1.3.

References

Credits

  • Vijay Mamidi (finder)

HTTP/2 framing vulnerabilities

CVE-2022-31780 [CVE] [CVE json] [OSV json]

Last updated: 2022-08-10T05:45:38.174Z

Affected

  • Apache Traffic Server at 8.0.0 to 9.1.2

Description

Improper Input Validation vulnerability in HTTP/2 frame handling of Apache Traffic Server allows an attacker to smuggle requests. This issue affects Apache Traffic Server 8.0.0 to 9.1.2.

References

Credits

  • Apache Traffic Server would like to thank Bahruz Jabiyev, Steven Sprecher, Anthony Gavazzi, Tommaso Innocenti, Kaan Onarlioglu, and Engin Kirda for reporting these issues.

Improper HTTP/2 scheme and method validation

CVE-2022-31779 [CVE] [CVE json] [OSV json]

Last updated: 2022-10-27T00:00:36.092Z

Affected

  • Apache Traffic Server at 8.0.0 to 9.1.2

Description

Improper Input Validation vulnerability in HTTP/2 header parsing of Apache Traffic Server allows an attacker to smuggle requests. This issue affects Apache Traffic Server 8.0.0 to 9.1.2.

References

Credits

  • Apache Traffic Server would like to thank Dhana Sekaran for reporting this issue.

Transfer-Encoding not treated as hop-by-hop

CVE-2022-31778 [CVE] [CVE json] [OSV json]

Last updated: 2022-08-10T05:44:15.239Z

Affected

  • Apache Traffic Server at 8.0.0 to 9.0.2

Description

Improper Input Validation vulnerability in handling the Transfer-Encoding header of Apache Traffic Server allows an attacker to poison the cache. This issue affects Apache Traffic Server 8.0.0 to 9.0.2.

References

Credits

  • Apache Traffic Server would like to thank Chris Lemmons for reporting this issue.

Insufficient Validation of HTTP/1.x Headers

CVE-2022-28129 [CVE] [CVE json] [OSV json]

Last updated: 2022-08-10T05:42:44.803Z

Affected

  • Apache Traffic Server at 8.0.0 to 9.1.2

Description

Improper Input Validation vulnerability in HTTP/1.1 header parsing of Apache Traffic Server allows an attacker to send invalid headers. This issue affects Apache Traffic Server 8.0.0 to 9.1.2.

References

Credits

  • Apache Traffic Server would like to thank Zhang Zeyu for reporting this issue.

Improper input validation on HTTP/2 headers

CVE-2022-25763 [CVE] [CVE json] [OSV json]

Last updated: 2022-10-20T20:25:04.197Z

Affected

  • Apache Traffic Server at 8.0.0 to 9.1.2

Description

Improper Input Validation vulnerability in HTTP/2 request validation of Apache Traffic Server allows an attacker to create smuggle or cache poison attacks. This issue affects Apache Traffic Server 8.0.0 to 9.1.2.

References

Credits

  • Apache Traffic Server would like to thank Mazakatsu Kitajo, Dhana Sekaran, and Zhang Zeyu for reporting this issue.

Improper authentication vulnerability in TLS origin verification

CVE-2021-44759 [CVE] [CVE json] [OSV json]

Last updated: 2022-03-23T14:03:27.211Z

Affected

  • Apache Traffic Server at 8.0.0 to 8.1.0

Description

Improper Authentication vulnerability in TLS origin validation of Apache Traffic Server allows an attacker to create a man in the middle attack. This issue affects Apache Traffic Server 8.0.0 to 8.1.0.

References

Credits

  • Apache Traffic Server would like to thank Takuya Kitano for reporting this issue.

HTTP request line fuzzing attacks

CVE-2021-44040 [CVE] [CVE json] [OSV json]

Last updated: 2022-03-23T14:04:02.939Z

Affected

  • Apache Traffic Server at 8.0.0 to 8.1.3 and 9.0.0 to 9.1.1

Description

Improper Input Validation vulnerability in request line parsing of Apache Traffic Server allows an attacker to send invalid requests. This issue affects Apache Traffic Server 8.0.0 to 8.1.3 and 9.0.0 to 9.1.1.

References

Credits

heap-buffer-overflow with stats-over-http plugin

CVE-2021-43082 [CVE] [CVE json] [OSV json]

Last updated: 2021-11-02T21:16:59.675Z

Affected

  • Apache Traffic Server at 9.1.0

Description

Buffer Copy without Checking Size of Input (‘Classic Buffer Overflow’) vulnerability in the stats-over-http plugin of Apache Traffic Server allows an attacker to overwrite memory. This issue affects Apache Traffic Server 9.1.0.

References

Credits

  • Apache Traffic Server would like to thank Masori Koshiba for finding this issue.

ATS stops accepting connections on FreeBSD

CVE-2021-41585 [CVE] [CVE json] [OSV json]

Last updated: 2021-11-02T21:16:43.796Z

Affected

  • Apache Traffic Server at 7.0.0 to 9.1.0

Description

Improper Input Validation vulnerability in accepting socket connections in Apache Traffic Server allows an attacker to make the server stop accepting new connections. This issue affects Apache Traffic Server 5.0.0 to 9.1.0.

References

Credits

  • Apache Traffic Server would like to thank Asbjorn Bjornstad for finding this issue.

Not validating origin TLS certificate

CVE-2021-38161 [CVE] [CVE json] [OSV json]

Last updated: 2021-11-02T21:16:04.785Z

Affected

  • Apache Traffic Server at 8.0.0 to 8.0.8

Description

Improper Authentication vulnerability in TLS origin verification of Apache Traffic Server allows for man in the middle attacks. This issue affects Apache Traffic Server 8.0.0 to 8.0.8.

References

Protocol vs scheme mismatch

CVE-2021-37150 [CVE] [CVE json] [OSV json]

Last updated: 2022-08-10T05:43:13.024Z

Affected

  • Apache Traffic Server at 8.0.0 to 9.1.2

Description

Improper Input Validation vulnerability in header parsing of Apache Traffic Server allows an attacker to request secure resources. This issue affects Apache Traffic Server 8.0.0 to 9.1.2.

References

Request Smuggling - multiple attacks

CVE-2021-37149 [CVE] [CVE json] [OSV json]

Last updated: 2021-11-02T21:15:10.588Z

Affected

  • Apache Traffic Server at 8.0.0 to 8.1.2 and 9.0.0 to 9.1.0

Description

Improper Input Validation vulnerability in header parsing of Apache Traffic Server allows an attacker to smuggle requests. This issue affects Apache Traffic Server 8.0.0 to 8.1.2 and 9.0.0 to 9.1.0.

References

Credits

  • Apache Traffic Server would like to thank Mattias Grenfeldt and Asta Olofsson for reporting this issue

Request Smuggling - transfer encoding validation

CVE-2021-37148 [CVE] [CVE json] [OSV json]

Last updated: 2021-11-02T21:14:46.545Z

Affected

  • Apache Traffic Server at 8.0.0 to 8.1.2 and 9.0.0 to 9.0.1

Description

Improper input validation vulnerability in header parsing of Apache Traffic Server allows an attacker to smuggle requests. This issue affects Apache Traffic Server 8.0.0 to 8.1.2 and 9.0.0 to 9.0.1.

References

Credits

  • Apache Traffic Server would like to thank Mattias Grenfeldt and Asta Olofsson for reporting this issue

Request Smuggling - LF line ending

CVE-2021-37147 [CVE] [CVE json] [OSV json]

Last updated: 2021-11-02T21:14:21.298Z

Affected

  • Apache Traffic Server at 8.0.0 to 8.1.2 and 9.0.0 to 9.1.0

Description

Improper input validation vulnerability in header parsing of Apache Traffic Server allows an attacker to smuggle requests. This issue affects Apache Traffic Server 8.0.0 to 8.1.2 and 9.0.0 to 9.1.0.

References

Credits

  • Apache Traffic Server would like to thank Mattias Grenfeldt and Asta Olofsson for reporting this issue.

Dynamic stack buffer overflow in cachekey plugin

CVE-2021-35474 [CVE] [CVE json] [OSV json]

Last updated: 2021-06-30T07:12:52.360Z

Affected

  • Apache Traffic Server at 7.0.0 to 7.1.12, 8.0.0 to 8.1.1, 9.0.0 to 9.0.1

Description

Stack-based Buffer Overflow vulnerability in cachekey plugin of Apache Traffic Server. This issue affects Apache Traffic Server 7.0.0 to 7.1.12, 8.0.0 to 8.1.1, 9.0.0 to 9.0.1.

References

Reading HTTP/2 frames too many times

CVE-2021-32567 [CVE] [CVE json] [OSV json]

Last updated: 2021-06-30T07:12:25.231Z

Affected

  • Apache Traffic Server at 7.0.0 to 7.1.12, 8.0.0 to 8.1.1, 9.0.0 to 9.0.1

Description

Improper Input Validation vulnerability in HTTP/2 of Apache Traffic Server allows an attacker to DOS the server. This issue affects Apache Traffic Server 7.0.0 to 7.1.12, 8.0.0 to 8.1.1, 9.0.0 to 9.0.1.

References

Specific sequence of HTTP/2 frames can cause ATS to crash

CVE-2021-32566 [CVE] [CVE json] [OSV json]

Last updated: 2021-06-30T07:11:47.425Z

Affected

  • Apache Traffic Server at 7.0.0 to 7.1.12, 8.0.0 to 8.1.1, 9.0.0 to 9.0.1

Description

Improper Input Validation vulnerability in HTTP/2 of Apache Traffic Server allows an attacker to DOS the server. This issue affects Apache Traffic Server 7.0.0 to 7.1.12, 8.0.0 to 8.1.1, 9.0.0 to 9.0.1.

References

HTTP Request Smuggling, content length with invalid charters

CVE-2021-32565 [CVE] [CVE json] [OSV json]

Last updated: 2021-06-28T17:31:31.239Z

Affected

  • Apache Traffic Server at 7.0.0 to 7.1.12, 8.0.0 to 8.1.1, 9.0.0 to 9.0.1

Description

Invalid values in the Content-Length header sent to Apache Traffic Server allows an attacker to smuggle requests. This issue affects Apache Traffic Server 7.0.0 to 7.1.12, 8.0.0 to 8.1.1, 9.0.0 to 9.0.1.

References

slicer plugin crash

CVE-2021-27737 [CVE] [CVE json]

Last updated: 2021-05-17T17:41:59.734Z

Affected

  • Apache Traffic Server at 9.0.0

Description

Apache Traffic Server 9.0.0 is vulnerable to a remote DOS attack on the experimental Slicer plugin.

Incorrect handling of url fragment leads to cache poisoning

CVE-2021-27577 [CVE] [CVE json] [OSV json]

Last updated: 2021-06-28T17:28:40.345Z

Affected

  • Apache Traffic Server at 7.0.0 to 7.1.12, 8.0.0 to 8.1.1, 9.0.0 to 9.0.1

Description

Incorrect handling of url fragment vulnerability of Apache Traffic Server allows an attacker to poison the cache. This issue affects Apache Traffic Server 7.0.0 to 7.1.12, 8.0.0 to 8.1.1, 9.0.0 to 9.0.1.

References

Apache Traffic Server negative cache option is vulnerable to a cache poisoning attack

CVE-2020-17509 [CVE] [CVE json] [OSV json]

Last updated: 2021-01-11T09:31:44.280Z

Affected

  • Apache Traffic Server from Apache Traffic Server through 6.2.3

Description

Apache Traffic Server negative cache option is vulnerable to a cache poisoning attack affecting versions 6.0.0 through 6.2.3, 7.0.0 through 7.1.10, and 8.0.0 through 8.0.7. If you have this option enabled, please upgrade or disable this feature.

References

Apache Traffic Server ESI plugin has a memory disclosure vulnerability

CVE-2020-17508 [CVE] [CVE json] [OSV json]

Last updated: 2021-01-11T09:27:29.639Z

Affected

  • Apache Traffic Server from Apache Traffic Server through 6.2.3

Description

The ESI plugin in Apache Traffic Server 6.0.0 to 6.2.3, 7.0.0 to 7.1.11, and 8.0.0 to 8.1.0 has a memory disclosure vulnerability. If you are running the plugin please upgrade to 7.1.12 or 8.1.1 or later.

References