cbcvebase.

Apache Traffic Server vulnerabilities

121 known vulnerabilities affecting apache/traffic_server.

Total CVEs
121
CISA KEV
1
actively exploited
Public exploits
1
Exploited in wild
1
Severity breakdown
CRITICAL22HIGH76MEDIUM23

Vulnerabilities

Page 3 of 7
CVE-2026-58178P3HIGHCVSS 7.5≥ 8.0.0, ≤ 8.1.9≥ 9.0.0, < 9.2.15+1 more2026-07-29
CVE-2026-58178 [HIGH] CWE-674 CVE-2026-58178: The Apache Traffic Server ESI plugin can recurse without bound and fetch attacker-controlled URLs. The Apache Traffic Server ESI plugin can recurse without bound and fetch attacker-controlled URLs. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.11, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.
nvd
CVE-2018-1318P3HIGHCVSS 7.5≥ 6.0.0, ≤ 6.2.2≥ 7.0.0, ≤ 7.1.32018-08-29
CVE-2018-1318 [HIGH] CWE-20 CVE-2018-1318: Adding method ACLs in remap.config can cause a segfault when the user makes a carefully crafted requ Adding method ACLs in remap.config can cause a segfault when the user makes a carefully crafted request. This affects versions Apache Traffic Server (ATS) 6.0.0 to 6.2.2 and 7.0.0 to 7.1.3. To resolve this issue users running 6.x should upgrade to 6.2.3 or later versions and 7.x users should upgrade to 7.1.4 or later versions.
nvd
CVE-2026-58151P3HIGHCVSS 7.5≥ 8.0.0, ≤ 8.1.9≥ 9.0.0, < 9.2.15+1 more2026-07-29
CVE-2026-58151 [HIGH] CWE-400 CVE-2026-58151: Apache Traffic Server can be crashed or driven to resource exhaustion by abusive HTTP/2 framing and Apache Traffic Server can be crashed or driven to resource exhaustion by abusive HTTP/2 framing and flow-control. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.11, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.
nvd
CVE-2026-65324P3HIGHCVSS 7.5≥ 8.0.0, ≤ 8.1.9≥ 9.0.0, < 9.2.15+1 more2026-07-29
CVE-2026-65324 [HIGH] CWE-400 CVE-2026-65324: Apache Traffic Server drops the per-stream buffer cap when dechunking HTTP/2 or HTTP/3 responses, le Apache Traffic Server drops the per-stream buffer cap when dechunking HTTP/2 or HTTP/3 responses, letting a slow client exhaust server memory. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.11, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.
nvd
CVE-2026-58183P3HIGHCVSS 7.5≥ 8.0.0, ≤ 8.1.9≥ 9.0.0, < 9.2.15+1 more2026-07-29
CVE-2026-58183 [HIGH] CWE-20 CVE-2026-58183: The Apache Traffic Server prefetch plugin can crash when processing attacker-influenced input. Th The Apache Traffic Server prefetch plugin can crash when processing attacker-influenced input. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.11, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.
nvd
CVE-2025-65114P3HIGHCVSS 7.5≥ 9.0.0, < 9.2.13≥ 10.0.0, < 10.1.22026-04-02
CVE-2025-65114 [HIGH] CWE-444 CVE-2025-65114: Apache Traffic Server allows request smuggling if chunked messages are malformed. This issue affec Apache Traffic Server allows request smuggling if chunked messages are malformed. This issue affects Apache Traffic Server: from 9.0.0 through 9.2.12, from 10.0.0 through 10.1.1. Users are recommended to upgrade to version 9.2.13 or 10.1.2, which fix the issue.
nvd
CVE-2026-59173P3HIGHCVSS 7.5≥ 9.0.0, < 9.2.14≥ 10.0.0, < 10.1.32026-07-18
CVE-2026-59173 [HIGH] CWE-400 CVE-2026-59173: Uncontrolled Resource Consumption vulnerability in Apache Traffic Server. This issue affects Apache Uncontrolled Resource Consumption vulnerability in Apache Traffic Server. This issue affects Apache Traffic Server: from 9.0.0 through 9.1.13, from 10.0.0 through 10.1.2. Users are recommended to upgrade to version 9.1.14 or 10.1.3, which fixes the issue.
nvd
CVE-2026-58161P3HIGHCVSS 7.5≥ 8.0.0, ≤ 8.1.9≥ 9.0.0, < 9.2.15+1 more2026-07-29
CVE-2026-58161 [HIGH] CWE-476 CVE-2026-58161: Apache Traffic Server can crash from null dereferences and dangling references in TLS and SNI handli Apache Traffic Server can crash from null dereferences and dangling references in TLS and SNI handling. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.11, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.
nvd
CVE-2026-58164P3HIGHCVSS 7.5≥ 8.0.0, ≤ 8.1.9≥ 9.0.0, < 9.2.15+1 more2026-07-29
CVE-2026-58164 [HIGH] CWE-416 CVE-2026-58164: Apache Traffic Server has use-after-free and time-of-check/time-of-use errors in remap configuration Apache Traffic Server has use-after-free and time-of-check/time-of-use errors in remap configuration handling. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.11, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.
nvd
CVE-2026-58189P3HIGHCVSS 7.5≥ 8.0.0, ≤ 8.1.9≥ 9.0.0, < 9.2.15+1 more2026-07-29
CVE-2026-58189 [HIGH] CWE-918 CVE-2026-58189: Apache Traffic Server allows redirect-limit bypass when plugins reset the retry counter, enabling SS Apache Traffic Server allows redirect-limit bypass when plugins reset the retry counter, enabling SSRF amplification. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.11, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.
nvd
CVE-2026-58184P3HIGHCVSS 7.5≥ 8.0.0, ≤ 8.1.9≥ 9.0.0, < 9.2.15+1 more2026-07-29
CVE-2026-58184 [HIGH] CWE-787 CVE-2026-58184: The Apache Traffic Server header_rewrite plugin can crash or corrupt memory during cookie operations The Apache Traffic Server header_rewrite plugin can crash or corrupt memory during cookie operations and CIDR condition matching. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.11, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.
nvd
CVE-2021-44759P3HIGHCVSS 8.1≥ 8.0.0, ≤ 8.1.02022-03-23
CVE-2021-44759 [HIGH] CWE-287 CVE-2021-44759: Improper Authentication vulnerability in TLS origin validation of Apache Traffic Server allows an at Improper Authentication vulnerability in TLS origin validation of Apache Traffic Server allows an attacker to create a man in the middle attack. This issue affects Apache Traffic Server 8.0.0 to 8.1.0.
nvd
CVE-2022-25763P3HIGHCVSS 7.5≥ 8.0.0, < 8.1.5≥ 9.0.0, < 9.1.32022-08-10
CVE-2022-25763 [HIGH] CWE-444 CVE-2022-25763: Improper Input Validation vulnerability in HTTP/2 request validation of Apache Traffic Server allows Improper Input Validation vulnerability in HTTP/2 request validation of Apache Traffic Server allows an attacker to create smuggle or cache poison attacks. This issue affects Apache Traffic Server 8.0.0 to 9.1.2.
nvd
CVE-2026-58175P3HIGHCVSS 7.5≥ 8.0.0, ≤ 8.1.9≥ 9.0.0, < 9.2.15+1 more2026-07-29
CVE-2026-58175 [HIGH] CWE-401 CVE-2026-58175: Apache Traffic Server leaks memory when handling HostDB SRV records. This issue affects Apache Tr Apache Traffic Server leaks memory when handling HostDB SRV records. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.11, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.
nvd
CVE-2024-53868P3HIGHCVSS 7.5≥ 9.0.0, < 9.2.10≥ 10.0.0, < 10.0.52025-04-03
CVE-2024-53868 [HIGH] CWE-444 CVE-2024-53868: Apache Traffic Server allows request smuggling if chunked messages are malformed. This issue a Apache Traffic Server allows request smuggling if chunked messages are malformed. This issue affects Apache Traffic Server: from 9.2.0 through 9.2.9, from 10.0.0 through 10.0.4. Users are recommended to upgrade to version 9.2.10 or 10.0.5, which fixes the issue.
nvd
CVE-2025-31698P3HIGHCVSS 7.5≥ 9.0.0, < 9.2.11≥ 10.0.0, < 10.0.62025-06-19
CVE-2025-31698 [HIGH] CWE-284 CVE-2025-31698: ACL configured in ip_allow.config or remap.config does not use IP addresses that are provided by PRO ACL configured in ip_allow.config or remap.config does not use IP addresses that are provided by PROXY protocol. Users can use a new setting (proxy.config.acl.subjects) to choose which IP addresses to use for the ACL if Apache Traffic Server is configured to accept PROXY protocol. This issue affects undefined: from 10.0.0 through 10.0.6, from 9.0.0 t
nvd
CVE-2021-38161P3HIGHCVSS 8.1≥ 8.0.0, ≤ 8.0.82021-11-03
CVE-2021-38161 [HIGH] CWE-287 CVE-2021-38161: Improper Authentication vulnerability in TLS origin verification of Apache Traffic Server allows for Improper Authentication vulnerability in TLS origin verification of Apache Traffic Server allows for man in the middle attacks. This issue affects Apache Traffic Server 8.0.0 to 8.0.8.
nvd
CVE-2021-27577P3HIGHCVSS 7.5≥ 7.0.0, ≤ 7.1.12≥ 8.0.0, ≤ 8.1.1+1 more2021-06-29
CVE-2021-27577 [HIGH] CWE-444 CVE-2021-27577: Incorrect handling of url fragment vulnerability of Apache Traffic Server allows an attacker to pois Incorrect handling of url fragment vulnerability of Apache Traffic Server allows an attacker to poison the cache. This issue affects Apache Traffic Server 7.0.0 to 7.1.12, 8.0.0 to 8.1.1, 9.0.0 to 9.0.1.
nvd
CVE-2024-35296P3HIGHCVSS 8.2≥ 8.0.0, < 8.1.11≥ 9.0.0, < 9.2.52024-07-26
CVE-2024-35296 [HIGH] CWE-20 CVE-2024-35296: Invalid Accept-Encoding header can cause Apache Traffic Server to fail cache lookup and force forwar Invalid Accept-Encoding header can cause Apache Traffic Server to fail cache lookup and force forwarding requests. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.10, from 9.0.0 through 9.2.4. Users are recommended to upgrade to version 8.1.11 or 9.2.5, which fixes the issue.
nvd
CVE-2022-31779P3HIGHCVSS 7.5≥ 8.0.0, ≤ 8.1.4≥ 9.0.0, ≤ 9.1.22022-08-10
CVE-2022-31779 [HIGH] CWE-20 CVE-2022-31779: Improper Input Validation vulnerability in HTTP/2 header parsing of Apache Traffic Server allows an Improper Input Validation vulnerability in HTTP/2 header parsing of Apache Traffic Server allows an attacker to smuggle requests. This issue affects Apache Traffic Server 8.0.0 to 9.1.2.
nvd
Apache Traffic Server vulnerabilities | cvebase