Apache Traffic Server vulnerabilities
121 known vulnerabilities affecting apache/traffic_server.
Total CVEs
121
CISA KEV
1
actively exploited
Public exploits
1
Exploited in wild
1
Severity breakdown
CRITICAL22HIGH76MEDIUM23
Vulnerabilities
Page 2 of 7
CVE-2026-58154P3HIGHCVSS 8.9≥ 8.0.0, ≤ 8.1.9≥ 9.0.0, < 9.2.15+1 more2026-07-29
CVE-2026-58154 [HIGH] CWE-787 CVE-2026-58154: Apache Traffic Server can write out of bounds or overflow integers while parsing MIME and HTTP heade
Apache Traffic Server can write out of bounds or overflow integers while parsing MIME and HTTP headers.
This issue affects Apache Traffic Server: from 8.0.0 through 8.1.11, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3.
Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.
nvd
CVE-2021-35474P3CRITICALCVSS 9.8≥ 7.0.0, ≤ 7.1.12≥ 8.0.0, ≤ 8.1.1+1 more2021-06-30
CVE-2021-35474 [CRITICAL] CWE-121 CVE-2021-35474: Stack-based Buffer Overflow vulnerability in cachekey plugin of Apache Traffic Server. This issue af
Stack-based Buffer Overflow vulnerability in cachekey plugin of Apache Traffic Server. This issue affects Apache Traffic Server 7.0.0 to 7.1.12, 8.0.0 to 8.1.1, 9.0.0 to 9.0.1.
nvd
CVE-2021-43082P3CRITICALCVSS 9.8≥ 8.0.0, ≤ 8.1.2≥ 9.0.0, ≤ 9.1.02021-11-03
CVE-2021-43082 [CRITICAL] CWE-120 CVE-2021-43082: Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in the stats-ov
Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in the stats-over-http plugin of Apache Traffic Server allows an attacker to overwrite memory. This issue affects Apache Traffic Server 9.1.0.
nvd
CVE-2026-58182P3HIGHCVSS 8.6≥ 8.0.0, ≤ 8.1.9≥ 9.0.0, < 9.2.15+1 more2026-07-29
CVE-2026-58182 [HIGH] CWE-400 CVE-2026-58182: The Apache Traffic Server ts_lua plugin mishandles initialization, transform context, and per-instan
The Apache Traffic Server ts_lua plugin mishandles initialization, transform context, and per-instance state.
This issue affects Apache Traffic Server: from 8.0.0 through 8.1.11, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3.
Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.
nvd
CVE-2024-50306P3CRITICALCVSS 9.1≥ 9.0.0, < 9.2.6≥ 10.0.0, < 10.0.22024-11-14
CVE-2024-50306 [CRITICAL] CWE-252 CVE-2024-50306: Unchecked return value can allow Apache Traffic Server to retain privileges on startup. This issue
Unchecked return value can allow Apache Traffic Server to retain privileges on startup.
This issue affects Apache Traffic Server: from 9.2.0 through 9.2.5, from 10.0.0 through 10.0.1.
Users are recommended to upgrade to version 9.2.6 or 10.0.2, which fixes the issue.
nvd
CVE-2019-9517P3HIGHCVSS 7.5≥ 6.0.0, ≤ 6.2.3≥ 7.0.0, ≤ 7.1.6+1 more2019-08-13
CVE-2019-9517 [HIGH] CWE-400 CVE-2019-9517: Some HTTP/2 implementations are vulnerable to unconstrained interal data buffering, potentially lead
Some HTTP/2 implementations are vulnerable to unconstrained interal data buffering, potentially leading to a denial of service. The attacker opens the HTTP/2 window so the peer can send without constraint; however, they leave the TCP window closed so the peer cannot actually write (many of) the bytes on the wire. The attacker then sends a stream of requ
nvd
CVE-2019-17559P3CRITICALCVSS 9.8≥ 6.0.0, ≤ 6.2.3≥ 7.0.0, ≤ 7.1.8+1 more2020-03-23
CVE-2019-17559 [CRITICAL] CWE-444 CVE-2019-17559: There is a vulnerability in Apache Traffic Server 6.0.0 to 6.2.3, 7.0.0 to 7.1.8, and 8.0.0 to 8.0.5
There is a vulnerability in Apache Traffic Server 6.0.0 to 6.2.3, 7.0.0 to 7.1.8, and 8.0.0 to 8.0.5 with a smuggling attack and scheme parsing. Upgrade to versions 7.1.9 and 8.0.6 or later versions.
nvd
CVE-2019-17565P3CRITICALCVSS 9.8≥ 6.0.0, ≤ 6.2.3≥ 7.0.0, ≤ 7.1.8+1 more2020-03-23
CVE-2019-17565 [CRITICAL] CWE-444 CVE-2019-17565: There is a vulnerability in Apache Traffic Server 6.0.0 to 6.2.3, 7.0.0 to 7.1.8, and 8.0.0 to 8.0.5
There is a vulnerability in Apache Traffic Server 6.0.0 to 6.2.3, 7.0.0 to 7.1.8, and 8.0.0 to 8.0.5 with a smuggling attack and chunked encoding. Upgrade to versions 7.1.9 and 8.0.6 or later versions.
nvd
CVE-2019-9518P3HIGHCVSS 7.5≥ 6.0.0, ≤ 6.2.3≥ 7.0.0, ≤ 7.1.6+1 more2019-08-13
CVE-2019-9518 [HIGH] CWE-400 CVE-2019-9518: Some HTTP/2 implementations are vulnerable to a flood of empty frames, potentially leading to a deni
Some HTTP/2 implementations are vulnerable to a flood of empty frames, potentially leading to a denial of service. The attacker sends a stream of frames with an empty payload and without the end-of-stream flag. These frames can be DATA, HEADERS, CONTINUATION and/or PUSH_PROMISE. The peer spends time processing each frame disproportionate to attack bandw
nvd
CVE-2019-9516P3MEDIUMCVSS 6.5≥ 6.0.0, ≤ 6.2.3≥ 7.0.0, ≤ 7.1.6+1 more2019-08-13
CVE-2019-9516 [MEDIUM] CWE-400 CVE-2019-9516: Some HTTP/2 implementations are vulnerable to a header leak, potentially leading to a denial of serv
Some HTTP/2 implementations are vulnerable to a header leak, potentially leading to a denial of service. The attacker sends a stream of headers with a 0-length header name and 0-length header value, optionally Huffman encoded into 1-byte or greater headers. Some implementations allocate memory for these headers and keep the allocation alive until the
nvd
CVE-2023-33934P3CRITICALCVSS 9.1≥ 8.0.0, ≤ 8.1.7≥ 9.0.0, ≤ 9.2.12023-08-09
CVE-2023-33934 [CRITICAL] CWE-444 CVE-2023-33934: Improper Input Validation vulnerability in Apache Software Foundation Apache Traffic Server.This iss
Improper Input Validation vulnerability in Apache Software Foundation Apache Traffic Server.This issue affects Apache Traffic Server: through 9.2.1.
nvd
CVE-2026-58159P3HIGHCVSS 8.2≥ 8.0.0, ≤ 8.1.9≥ 9.0.0, < 9.2.15+1 more2026-07-29
CVE-2026-58159 [HIGH] CWE-863 CVE-2026-58159: Apache Traffic Server can bypass IP access controls on UDS listeners and through ACL matching errors
Apache Traffic Server can bypass IP access controls on UDS listeners and through ACL matching errors.
This issue affects Apache Traffic Server: from 8.0.0 through 8.1.11, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3.
Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.
nvd
CVE-2026-58153P3HIGHCVSS 8.3≥ 10.0.0, < 10.1.42026-07-29
CVE-2026-58153 [HIGH] CWE-444 CVE-2026-58153: Apache Traffic Server forwards HTTP/2 origin trailers to HTTP/1 clients without proper chunked frami
Apache Traffic Server forwards HTTP/2 origin trailers to HTTP/1 clients without proper chunked framing when converting HTTP/2 to HTTP/1.
This issue affects Apache Traffic Server: from 10.0.0 through 10.1.3.
Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.
nvd
CVE-2026-58188P3HIGHCVSS 8.2≥ 8.0.0, ≤ 8.1.9≥ 9.0.0, < 9.2.15+1 more2026-07-29
CVE-2026-58188 [HIGH] CWE-787 CVE-2026-58188: Several Apache Traffic Server experimental plugins have memory-safety and limit-bypass errors. Th
Several Apache Traffic Server experimental plugins have memory-safety and limit-bypass errors.
This issue affects Apache Traffic Server: from 8.0.0 through 8.1.11, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3.
Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.
nvd
CVE-2015-3249P3CRITICALCVSS 9.8v5.3.02017-10-30
CVE-2015-3249 [CRITICAL] CWE-119 CVE-2015-3249: The HTTP/2 experimental feature in Apache Traffic Server 5.3.x before 5.3.1 allows remote attackers
The HTTP/2 experimental feature in Apache Traffic Server 5.3.x before 5.3.1 allows remote attackers to cause a denial of service (out-of-bounds access and daemon crash) or possibly execute arbitrary code via vectors related to the (1) frame_handlers array or (2) set_dynamic_table_size function.
nvd
CVE-2020-1944P3CRITICALCVSS 9.8≥ 6.0.0, ≤ 6.2.3≥ 7.0.0, ≤ 7.1.8+1 more2020-03-23
CVE-2020-1944 [CRITICAL] CWE-444 CVE-2020-1944: There is a vulnerability in Apache Traffic Server 6.0.0 to 6.2.3, 7.0.0 to 7.1.8, and 8.0.0 to 8.0.5
There is a vulnerability in Apache Traffic Server 6.0.0 to 6.2.3, 7.0.0 to 7.1.8, and 8.0.0 to 8.0.5 with a smuggling attack and Transfer-Encoding and Content length headers. Upgrade to versions 7.1.9 and 8.0.6 or later versions.
nvd
CVE-2026-58186P3HIGHCVSS 7.5≥ 8.0.0, ≤ 8.1.9≥ 9.0.0, < 9.2.15+1 more2026-07-29
CVE-2026-58186 [HIGH] CWE-20 CVE-2026-58186: The Apache Traffic Server webp_transform plugin can decode unsafely and serve mislabeled, cacheable
The Apache Traffic Server webp_transform plugin can decode unsafely and serve mislabeled, cacheable responses.
This issue affects Apache Traffic Server: from 8.0.0 through 8.1.11, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3.
Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.
nvd
CVE-2025-58136P3HIGHCVSS 7.5≥ 9.0.0, < 9.2.13≥ 10.0.0, < 10.1.22026-04-02
CVE-2025-58136 [HIGH] CWE-670 CVE-2025-58136: A bug in POST request handling causes a crash under a certain condition. This issue affects Apache
A bug in POST request handling causes a crash under a certain condition.
This issue affects Apache Traffic Server: from 10.0.0 through 10.1.1, from 9.0.0 through 9.2.12.
Users are recommended to upgrade to version 10.1.2 or 9.2.13, which fix the issue.
A workaround for older versions is to set proxy.config.http.request_buffer_enabled to 0 (the defaul
nvd
CVE-2026-58180P3HIGHCVSS 7.5≥ 8.0.0, ≤ 8.1.9≥ 9.0.0, < 9.2.15+1 more2026-07-29
CVE-2026-58180 [HIGH] CWE-121 CVE-2026-58180: The Apache Traffic Server txn_box plugin overflows the stack from attacker-controlled input. This
The Apache Traffic Server txn_box plugin overflows the stack from attacker-controlled input.
This issue affects Apache Traffic Server: from 8.0.0 through 8.1.11, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3.
Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.
nvd
CVE-2026-58181P3HIGHCVSS 7.5≥ 8.0.0, ≤ 8.1.9≥ 9.0.0, < 9.2.15+1 more2026-07-29
CVE-2026-58181 [HIGH] CWE-121 CVE-2026-58181: The Apache Traffic Server uri_signing and url_sig plugins can exhaust the stack or crash on attacker
The Apache Traffic Server uri_signing and url_sig plugins can exhaust the stack or crash on attacker input.
This issue affects Apache Traffic Server: from 8.0.0 through 8.1.11, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3.
Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.
nvd