Apache Traffic Server vulnerabilities
121 known vulnerabilities affecting apache/traffic_server.
Total CVEs
121
CISA KEV
1
actively exploited
Public exploits
1
Exploited in wild
1
Severity breakdown
CRITICAL22HIGH76MEDIUM23
Vulnerabilities
Page 1 of 7
CVE-2023-44487P1HIGHCVSS 7.5KEVPoC≥ 8.0.0, < 8.1.9≥ 9.0.0, < 9.2.32023-10-10
CVE-2023-44487 [HIGH] CWE-400 CVE-2023-44487: The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancell
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.
nvd
CVE-2024-31309P2HIGHCVSS 7.5≥ 8.0.0, < 8.1.10≥ 9.0.0, < 9.2.42024-04-10
CVE-2024-31309 [HIGH] CWE-20 CVE-2024-31309: HTTP/2 CONTINUATION DoS attack can cause Apache Traffic Server to consume more resources on the serv
HTTP/2 CONTINUATION DoS attack can cause Apache Traffic Server to consume more resources on the server. Version from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.3 are affected.
Users can set a new setting (proxy.config.http2.max_continuation_frames_per_minute) to limit the number of CONTINUATION frames per minute. ATS does have a fixed amount of memor
nvd
CVE-2019-9515P3HIGHCVSS 7.5≥ 6.0.0, ≤ 6.2.3≥ 7.0.0, ≤ 7.1.6+1 more2019-08-13
CVE-2019-9515 [HIGH] CWE-400 CVE-2019-9515: Some HTTP/2 implementations are vulnerable to a settings flood, potentially leading to a denial of s
Some HTTP/2 implementations are vulnerable to a settings flood, potentially leading to a denial of service. The attacker sends a stream of SETTINGS frames to the peer. Since the RFC requires that the peer reply with one acknowledgement per SETTINGS frame, an empty SETTINGS frame is almost equivalent in behavior to a ping. Depending on how efficiently th
nvd
CVE-2019-9513P3HIGHCVSS 7.5≥ 6.0.0, ≤ 6.2.3≥ 7.0.0, ≤ 7.1.6+1 more2019-08-13
CVE-2019-9513 [HIGH] CWE-400 CVE-2019-9513: Some HTTP/2 implementations are vulnerable to resource loops, potentially leading to a denial of ser
Some HTTP/2 implementations are vulnerable to resource loops, potentially leading to a denial of service. The attacker creates multiple request streams and continually shuffles the priority of the streams in a way that causes substantial churn to the priority tree. This can consume excess CPU.
nvd
CVE-2019-9512P3HIGHCVSS 7.5≥ 6.0.0, ≤ 6.2.3≥ 7.0.0, ≤ 7.1.6+1 more2019-08-13
CVE-2019-9512 [HIGH] CWE-400 CVE-2019-9512: Some HTTP/2 implementations are vulnerable to ping floods, potentially leading to a denial of servic
Some HTTP/2 implementations are vulnerable to ping floods, potentially leading to a denial of service. The attacker sends continual pings to an HTTP/2 peer, causing the peer to build an internal queue of responses. Depending on how efficiently this data is queued, this can consume excess CPU, memory, or both.
nvd
CVE-2019-9514P3HIGHCVSS 7.5≥ 6.0.0, ≤ 6.2.3≥ 7.0.0, ≤ 7.1.6+1 more2019-08-13
CVE-2019-9514 [HIGH] CWE-400 CVE-2019-9514: Some HTTP/2 implementations are vulnerable to a reset flood, potentially leading to a denial of serv
Some HTTP/2 implementations are vulnerable to a reset flood, potentially leading to a denial of service. The attacker opens a number of streams and sends an invalid request over each stream that should solicit a stream of RST_STREAM frames from the peer. Depending on how the peer queues the RST_STREAM frames, this can consume excess memory, CPU, or both
nvd
CVE-2026-57834P2CRITICALCVSS 10.0≥ 8.0.0, ≤ 8.1.9≥ 9.0.0, < 9.2.15+1 more2026-07-29
CVE-2026-57834 [CRITICAL] CWE-444 CVE-2026-57834: Apache Traffic Server allows request smuggling if chunked messages are malformed. This issue affe
Apache Traffic Server allows request smuggling if chunked messages are malformed.
This issue affects Apache Traffic Server: from 8.0.0 through 8.1.11, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3.
Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.
nvd
CVE-2026-58150P2CRITICALCVSS 10.0≥ 8.0.0, ≤ 8.1.9≥ 9.0.0, < 9.2.15+1 more2026-07-29
CVE-2026-58150 [CRITICAL] CWE-444 CVE-2026-58150: Apache Traffic Server does not reject Transfer-Encoding in HTTP/2 requests, allowing downgrade reque
Apache Traffic Server does not reject Transfer-Encoding in HTTP/2 requests, allowing downgrade request smuggling.
This issue affects Apache Traffic Server: from 8.0.0 through 8.1.11, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3.
Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.
nvd
CVE-2026-58162P2CRITICALCVSS 10.0≥ 8.0.0, ≤ 8.1.9≥ 9.0.0, < 9.2.15+1 more2026-07-29
CVE-2026-58162 [CRITICAL] CWE-295 CVE-2026-58162: The Apache Traffic Server certifier plugin generates certificates based on attacker-controlled clien
The Apache Traffic Server certifier plugin generates certificates based on attacker-controlled client SNI.
This issue affects Apache Traffic Server: from 8.0.0 through 8.1.11, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3.
Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.
nvd
CVE-2019-9511P3HIGHCVSS 7.5≥ 6.0.0, ≤ 6.2.3≥ 7.0.0, ≤ 7.1.6+1 more2019-08-13
CVE-2019-9511 [HIGH] CWE-400 CVE-2019-9511: Some HTTP/2 implementations are vulnerable to window size manipulation and stream prioritization man
Some HTTP/2 implementations are vulnerable to window size manipulation and stream prioritization manipulation, potentially leading to a denial of service. The attacker requests a large amount of data from a specified resource over multiple streams. They manipulate window size and stream priority to force the server to queue the data in 1-byte chunks. De
nvd
CVE-2026-58179P2CRITICALCVSS 9.8≥ 8.0.0, ≤ 8.1.9≥ 9.0.0, < 9.2.15+1 more2026-07-29
CVE-2026-58179 [CRITICAL] CWE-121 CVE-2026-58179: The Apache Traffic Server regex_remap plugin overflows the stack and integers from substitution inpu
The Apache Traffic Server regex_remap plugin overflows the stack and integers from substitution input.
This issue affects Apache Traffic Server: from 8.0.0 through 8.1.11, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3.
Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.
nvd
CVE-2023-39456P3HIGHCVSS 7.5≥ 9.0.0, < 9.2.32023-10-17
CVE-2023-39456 [HIGH] CWE-20 CVE-2023-39456: Improper Input Validation vulnerability in Apache Traffic Server with malformed HTTP/2 frames.This i
Improper Input Validation vulnerability in Apache Traffic Server with malformed HTTP/2 frames.This issue affects Apache Traffic Server: from 9.0.0 through 9.2.2.
Users are recommended to upgrade to version 9.2.3, which fixes the issue.
nvd
CVE-2026-58185P2CRITICALCVSS 9.8≥ 8.0.0, ≤ 8.1.9≥ 9.0.0, < 9.2.15+1 more2026-07-29
CVE-2026-58185 [CRITICAL] CWE-416 CVE-2026-58185: The Apache Traffic Server intercept plugin has a use-after-free. This issue affects Apache Traffi
The Apache Traffic Server intercept plugin has a use-after-free.
This issue affects Apache Traffic Server: from 8.0.0 through 8.1.11, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3.
Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.
nvd
CVE-2026-58155P2CRITICALCVSS 9.3≥ 8.0.0, ≤ 8.1.9≥ 9.0.0, < 9.2.15+1 more2026-07-29
CVE-2026-58155 [CRITICAL] CWE-444 CVE-2026-58155: Apache Traffic Server truncates over-long header names, allowing header aliasing, request smuggling,
Apache Traffic Server truncates over-long header names, allowing header aliasing, request smuggling, and policy bypass.
This issue affects Apache Traffic Server: from 8.0.0 through 8.1.11, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3.
Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.
nvd
CVE-2026-58177P2CRITICALCVSS 9.8≥ 10.0.0, < 10.1.42026-07-29
CVE-2026-58177 [CRITICAL] CWE-787 CVE-2026-58177: The Apache Traffic Server Cripts framework has out-of-bounds writes, path traversal, and use-after-f
The Apache Traffic Server Cripts framework has out-of-bounds writes, path traversal, and use-after-free errors.
This issue affects Apache Traffic Server: from 10.0.0 through 10.1.3.
Users are recommended to upgrade to version 10.1.4, which fix the issue.
nvd
CVE-2026-58163P2CRITICALCVSS 9.1≥ 8.0.0, ≤ 8.1.9≥ 9.0.0, < 9.2.15+1 more2026-07-29
CVE-2026-58163 [CRITICAL] CWE-502 CVE-2026-58163: Apache Traffic Server mishandles on-disk cache fields and object lifetimes, corrupting state or cras
Apache Traffic Server mishandles on-disk cache fields and object lifetimes, corrupting state or crashing.
This issue affects Apache Traffic Server: from 8.0.0 through 8.1.11, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3.
Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.
nvd
CVE-2026-33267P2CRITICALCVSS 9.1≥ 9.2.0, < 9.2.15≥ 10.0.0, < 10.1.42026-07-29
CVE-2026-33267 [CRITICAL] CWE-20 CVE-2026-33267: Improper Input Validation vulnerability in Apache Traffic Server. This issue affects Apache Traffic
Improper Input Validation vulnerability in Apache Traffic Server.
This issue affects Apache Traffic Server: from 9.2.0 through 9.2.14, from 10.1.0 through 10.1.3.
Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fixes the issue.
nvd
CVE-2026-58157P2HIGHCVSS 8.7≥ 8.0.0, ≤ 8.1.9≥ 9.0.0, < 9.2.15+1 more2026-07-29
CVE-2026-58157 [HIGH] CWE-200 CVE-2026-58157: Apache Traffic Server can reuse server sessions and tunnels improperly, exposing data across client
Apache Traffic Server can reuse server sessions and tunnels improperly, exposing data across client connections.
This issue affects Apache Traffic Server: from 8.0.0 through 8.1.11, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3.
Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.
nvd
CVE-2026-41920P3CRITICALCVSS 9.3≥ 9.0.0, < 9.2.15≥ 10.0.0, < 10.1.42026-07-29
CVE-2026-41920 [CRITICAL] CWE-284 CVE-2026-41920: Improper Access Control vulnerability in Apache Traffic Server. This issue affects Apache Traffic S
Improper Access Control vulnerability in Apache Traffic Server.
This issue affects Apache Traffic Server: from 9.0.0 through 9.1.14, from 10.0.0 through 10.1.3.
Users are recommended to upgrade to version 9.1.15 or 10.1.4, which fixes the issue.
nvd
CVE-2014-3624P3CRITICALCVSS 9.8v5.1.02017-10-30
CVE-2014-3624 [CRITICAL] CWE-284 CVE-2014-3624: Apache Traffic Server 5.1.x before 5.1.1 allows remote attackers to bypass access restrictions by le
Apache Traffic Server 5.1.x before 5.1.1 allows remote attackers to bypass access restrictions by leveraging failure to properly tunnel remap requests using CONNECT.
nvd
1 / 7Next →