CVE-2024-50305
published 2024-11-14CVE-2024-50305: Valid Host header field can cause Apache Traffic Server to crash on some platforms. This issue affects Apache Traffic Server: from 9.2.0 through 9.2.5. Users…
PriorityP339high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
0.93%
57.1th percentile
Valid Host header field can cause Apache Traffic Server to crash on some platforms.
This issue affects Apache Traffic Server: from 9.2.0 through 9.2.5.
Users are recommended to upgrade to version 9.2.6, which fixes the issue, or 10.0.2, which does not have the issue.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | traffic_server | >= 9.0.0 < 9.2.6 | 9.2.6 |
| apache_software_foundation | apache_traffic_server | 9.2.0 – 9.2.5 | — |
| debian | trafficserver | < trafficserver 9.2.5+ds-0+deb12u2 (bookworm) | trafficserver 9.2.5+ds-0+deb12u2 (bookworm) |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
osv7.5HIGH
vendor_debian7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Apache Traffic Server vulnerability
vendor_ubuntu·2026-02-18
CVE-2024-50305 Apache Traffic Server vulnerability
Title: Apache Traffic Server vulnerability
Summary: trafficserver could be made to crash if it received specially crafted
input.
Masakazu Kitajo discovered that Apache Traffic Server did not properly
handle the Valid Host header field. An attacker could possibly use this
issue to cause a denial of service (DoS).
Instructions: After a standard system update you need to restart Apache Traffic Server
to make all the necessary changes.
Debian
CVE-2024-50305: trafficserver - Valid Host header field can cause Apache Traffic Server to crash on some platfor...
vendor_debian·2024·CVSS 7.5
CVE-2024-50305 [HIGH] CVE-2024-50305: trafficserver - Valid Host header field can cause Apache Traffic Server to crash on some platfor...
Valid Host header field can cause Apache Traffic Server to crash on some platforms. This issue affects Apache Traffic Server: from 9.2.0 through 9.2.5. Users are recommended to upgrade to version 9.2.6, which fixes the issue, or 10.0.2, which does not have the issue.
Scope: local
bookworm: resolved (fixed in 9.2.5+ds-0+deb12u2)
bullseye: open
sid: open
GHSA
GHSA-45gh-j7vr-755q: Valid Host header field can cause Apache Traffic Server to crash on some platforms
ghsa_unreviewed·2024-11-14
CVE-2024-50305 [HIGH] CWE-120 GHSA-45gh-j7vr-755q: Valid Host header field can cause Apache Traffic Server to crash on some platforms
Valid Host header field can cause Apache Traffic Server to crash on some platforms.
This issue affects Apache Traffic Server: from 9.2.0 through 9.2.5.
Users are recommended to upgrade to version 9.2.6, which fixes the issue, or 10.0.2, which does not have the issue.
OSV
CVE-2024-50305: Valid Host header field can cause Apache Traffic Server to crash on some platforms
osv·2024-11-14·CVSS 7.5
CVE-2024-50305 [HIGH] CVE-2024-50305: Valid Host header field can cause Apache Traffic Server to crash on some platforms
Valid Host header field can cause Apache Traffic Server to crash on some platforms. This issue affects Apache Traffic Server: from 9.2.0 through 9.2.5. Users are recommended to upgrade to version 9.2.6, which fixes the issue, or 10.0.2, which does not have the issue.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2024-11-14
Published