cbcvebase.

Apache Traffic Server vulnerabilities

82 known vulnerabilities affecting apache/traffic_server.

Total CVEs
82
CISA KEV
1
actively exploited
Public exploits
1
Exploited in wild
1
Severity breakdown
CRITICAL12HIGH56MEDIUM14

Vulnerabilities

Page 2 of 5
CVE-2018-1318P3HIGHCVSS 7.5≥ 6.0.0, ≤ 6.2.2≥ 7.0.0, ≤ 7.1.32018-08-29
CVE-2018-1318 [HIGH] CWE-20 CVE-2018-1318: Adding method ACLs in remap.config can cause a segfault when the user makes a carefully crafted requ Adding method ACLs in remap.config can cause a segfault when the user makes a carefully crafted request. This affects versions Apache Traffic Server (ATS) 6.0.0 to 6.2.2 and 7.0.0 to 7.1.3. To resolve this issue users running 6.x should upgrade to 6.2.3 or later versions and 7.x users should upgrade to 7.1.4 or later versions.
nvd
CVE-2025-58136P3HIGHCVSS 7.5≥ 9.0.0, < 9.2.13≥ 10.0.0, < 10.1.22026-04-02
CVE-2025-58136 [HIGH] CWE-670 CVE-2025-58136: A bug in POST request handling causes a crash under a certain condition. This issue affects Apache A bug in POST request handling causes a crash under a certain condition. This issue affects Apache Traffic Server: from 10.0.0 through 10.1.1, from 9.0.0 through 9.2.12. Users are recommended to upgrade to version 10.1.2 or 9.2.13, which fix the issue. A workaround for older versions is to set proxy.config.http.request_buffer_enabled to 0 (the defaul
nvd
CVE-2025-65114P3HIGHCVSS 7.5≥ 9.0.0, < 9.2.13≥ 10.0.0, < 10.1.22026-04-02
CVE-2025-65114 [HIGH] CWE-444 CVE-2025-65114: Apache Traffic Server allows request smuggling if chunked messages are malformed. This issue affec Apache Traffic Server allows request smuggling if chunked messages are malformed. This issue affects Apache Traffic Server: from 9.0.0 through 9.2.12, from 10.0.0 through 10.1.1. Users are recommended to upgrade to version 9.2.13 or 10.1.2, which fix the issue.
nvd
CVE-2024-35296P3HIGHCVSS 8.2≥ 8.0.0, < 8.1.11≥ 9.0.0, < 9.2.52024-07-26
CVE-2024-35296 [HIGH] CWE-20 CVE-2024-35296: Invalid Accept-Encoding header can cause Apache Traffic Server to fail cache lookup and force forwar Invalid Accept-Encoding header can cause Apache Traffic Server to fail cache lookup and force forwarding requests. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.10, from 9.0.0 through 9.2.4. Users are recommended to upgrade to version 8.1.11 or 9.2.5, which fixes the issue.
nvd
CVE-2022-25763P3HIGHCVSS 7.5≥ 8.0.0, < 8.1.5≥ 9.0.0, < 9.1.32022-08-10
CVE-2022-25763 [HIGH] CWE-444 CVE-2022-25763: Improper Input Validation vulnerability in HTTP/2 request validation of Apache Traffic Server allows Improper Input Validation vulnerability in HTTP/2 request validation of Apache Traffic Server allows an attacker to create smuggle or cache poison attacks. This issue affects Apache Traffic Server 8.0.0 to 9.1.2.
nvd
CVE-2024-53868P3HIGHCVSS 7.5≥ 9.0.0, < 9.2.10≥ 10.0.0, < 10.0.52025-04-03
CVE-2024-53868 [HIGH] CWE-444 CVE-2024-53868: Apache Traffic Server allows request smuggling if chunked messages are malformed. This issue a Apache Traffic Server allows request smuggling if chunked messages are malformed. This issue affects Apache Traffic Server: from 9.2.0 through 9.2.9, from 10.0.0 through 10.0.4. Users are recommended to upgrade to version 9.2.10 or 10.0.5, which fixes the issue.
nvd
CVE-2025-31698P3HIGHCVSS 7.5≥ 9.0.0, < 9.2.11≥ 10.0.0, < 10.0.62025-06-19
CVE-2025-31698 [HIGH] CWE-284 CVE-2025-31698: ACL configured in ip_allow.config or remap.config does not use IP addresses that are provided by PRO ACL configured in ip_allow.config or remap.config does not use IP addresses that are provided by PROXY protocol. Users can use a new setting (proxy.config.acl.subjects) to choose which IP addresses to use for the ACL if Apache Traffic Server is configured to accept PROXY protocol. This issue affects undefined: from 10.0.0 through 10.0.6, from 9.0.0 t
nvd
CVE-2021-38161P3HIGHCVSS 8.1≥ 8.0.0, ≤ 8.0.82021-11-03
CVE-2021-38161 [HIGH] CWE-287 CVE-2021-38161: Improper Authentication vulnerability in TLS origin verification of Apache Traffic Server allows for Improper Authentication vulnerability in TLS origin verification of Apache Traffic Server allows for man in the middle attacks. This issue affects Apache Traffic Server 8.0.0 to 8.0.8.
nvd
CVE-2021-44759P3HIGHCVSS 8.1≥ 8.0.0, ≤ 8.1.02022-03-23
CVE-2021-44759 [HIGH] CWE-287 CVE-2021-44759: Improper Authentication vulnerability in TLS origin validation of Apache Traffic Server allows an at Improper Authentication vulnerability in TLS origin validation of Apache Traffic Server allows an attacker to create a man in the middle attack. This issue affects Apache Traffic Server 8.0.0 to 8.1.0.
nvd
CVE-2021-44040P3HIGHCVSS 7.5≥ 8.0.0, ≤ 8.1.3≥ 9.0.0, ≤ 9.1.12022-03-23
CVE-2021-44040 [HIGH] CWE-20 CVE-2021-44040: Improper Input Validation vulnerability in request line parsing of Apache Traffic Server allows an a Improper Input Validation vulnerability in request line parsing of Apache Traffic Server allows an attacker to send invalid requests. This issue affects Apache Traffic Server 8.0.0 to 8.1.3 and 9.0.0 to 9.1.1.
nvd
CVE-2022-31779P3HIGHCVSS 7.5≥ 8.0.0, ≤ 8.1.4≥ 9.0.0, ≤ 9.1.22022-08-10
CVE-2022-31779 [HIGH] CWE-20 CVE-2022-31779: Improper Input Validation vulnerability in HTTP/2 header parsing of Apache Traffic Server allows an Improper Input Validation vulnerability in HTTP/2 header parsing of Apache Traffic Server allows an attacker to smuggle requests. This issue affects Apache Traffic Server 8.0.0 to 9.1.2.
nvd
CVE-2021-37150P3HIGHCVSS 7.5≥ 8.0.0, ≤ 8.1.4≥ 9.0.0, ≤ 9.1.22022-08-10
CVE-2021-37150 [HIGH] CWE-20 CVE-2021-37150: Improper Input Validation vulnerability in header parsing of Apache Traffic Server allows an attacke Improper Input Validation vulnerability in header parsing of Apache Traffic Server allows an attacker to request secure resources. This issue affects Apache Traffic Server 8.0.0 to 9.1.2.
nvd
CVE-2017-5660P3HIGHCVSS 8.6≤ 6.2.0v6.2.1+2 more2018-02-27
CVE-2017-5660 [HIGH] CWE-20 CVE-2017-5660: There is a vulnerability in Apache Traffic Server (ATS) 6.2.0 and prior and 7.0.0 and prior with the There is a vulnerability in Apache Traffic Server (ATS) 6.2.0 and prior and 7.0.0 and prior with the Host header and line folding. This can have issues when interacting with upstream proxies and the wrong host being used.
nvd
CVE-2021-27577P3HIGHCVSS 7.5≥ 7.0.0, ≤ 7.1.12≥ 8.0.0, ≤ 8.1.1+1 more2021-06-29
CVE-2021-27577 [HIGH] CWE-444 CVE-2021-27577: Incorrect handling of url fragment vulnerability of Apache Traffic Server allows an attacker to pois Incorrect handling of url fragment vulnerability of Apache Traffic Server allows an attacker to poison the cache. This issue affects Apache Traffic Server 7.0.0 to 7.1.12, 8.0.0 to 8.1.1, 9.0.0 to 9.0.1.
nvd
CVE-2023-30631P3HIGHCVSS 7.5≥ 8.0.0, < 8.1.7≥ 9.0.0, < 9.2.12023-06-14
CVE-2023-30631 [HIGH] CWE-20 CVE-2023-30631: Improper Input Validation vulnerability in Apache Software Foundation Apache Traffic Server. The co Improper Input Validation vulnerability in Apache Software Foundation Apache Traffic Server. The configuration option proxy.config.http.push_method_enabled didn't function. However, by default the PUSH method is blocked in the ip_allow configuration file.This issue affects Apache Traffic Server: from 8.0.0 through 9.2.0. 8.x users should upgrade to 8.1
nvd
CVE-2022-28129P3HIGHCVSS 7.5≥ 8.0.0, ≤ 8.1.4≥ 9.0.0, ≤ 9.1.22022-08-10
CVE-2022-28129 [HIGH] CWE-20 CVE-2022-28129: Improper Input Validation vulnerability in HTTP/1.1 header parsing of Apache Traffic Server allows a Improper Input Validation vulnerability in HTTP/1.1 header parsing of Apache Traffic Server allows an attacker to send invalid headers. This issue affects Apache Traffic Server 8.0.0 to 9.1.2.
nvd
CVE-2022-31780P3HIGHCVSS 7.5≥ 8.0.0, ≤ 8.1.4≥ 9.0.0, ≤ 9.1.22022-08-10
CVE-2022-31780 [HIGH] CWE-20 CVE-2022-31780: Improper Input Validation vulnerability in HTTP/2 frame handling of Apache Traffic Server allows an Improper Input Validation vulnerability in HTTP/2 frame handling of Apache Traffic Server allows an attacker to smuggle requests. This issue affects Apache Traffic Server 8.0.0 to 9.1.2.
nvd
CVE-2018-8022P3HIGHCVSS 7.5≥ 6.0.0, ≤ 6.2.22018-08-29
CVE-2018-8022 [HIGH] CWE-20 CVE-2018-8022: A carefully crafted invalid TLS handshake can cause Apache Traffic Server (ATS) to segfault. This af A carefully crafted invalid TLS handshake can cause Apache Traffic Server (ATS) to segfault. This affects version 6.2.2. To resolve this issue users running 6.2.2 should upgrade to 6.2.3 or later versions.
nvd
CVE-2023-38522P3HIGHCVSS 7.5≥ 8.0.0, < 8.1.11≥ 9.0.0, < 9.2.52024-07-26
CVE-2023-38522 [HIGH] CWE-444 CVE-2023-38522: Apache Traffic Server accepts characters that are not allowed for HTTP field names and forwards malf Apache Traffic Server accepts characters that are not allowed for HTTP field names and forwards malformed requests to origin servers. This can be utilized for request smuggling and may also lead cache poisoning if the origin servers are vulnerable. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.10, from 9.0.0 through 9.2.4. Users a
nvd
CVE-2024-35161P3HIGHCVSS 7.5≥ 8.0.0, < 8.1.11≥ 9.0.0, < 9.2.52024-07-26
CVE-2024-35161 [HIGH] CWE-444 CVE-2024-35161: Apache Traffic Server forwards malformed HTTP chunked trailer section to origin servers. This can be Apache Traffic Server forwards malformed HTTP chunked trailer section to origin servers. This can be utilized for request smuggling and may also lead cache poisoning if the origin servers are vulnerable. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.10, from 9.0.0 through 9.2.4. Users can set a new setting (proxy.config.http.drop_
nvd
Apache Traffic Server vulnerabilities | cvebase