Apache Traffic Server vulnerabilities
121 known vulnerabilities affecting apache/traffic_server.
Total CVEs
121
CISA KEV
1
actively exploited
Public exploits
1
Exploited in wild
1
Severity breakdown
CRITICAL22HIGH76MEDIUM23
Vulnerabilities
Page 4 of 7
CVE-2021-37150P3HIGHCVSS 7.5≥ 8.0.0, ≤ 8.1.4≥ 9.0.0, ≤ 9.1.22022-08-10
CVE-2021-37150 [HIGH] CWE-20 CVE-2021-37150: Improper Input Validation vulnerability in header parsing of Apache Traffic Server allows an attacke
Improper Input Validation vulnerability in header parsing of Apache Traffic Server allows an attacker to request secure resources. This issue affects Apache Traffic Server 8.0.0 to 9.1.2.
nvd
CVE-2026-58187P3HIGHCVSS 7.5≥ 8.0.0, ≤ 8.1.9≥ 9.0.0, < 9.2.15+1 more2026-07-29
CVE-2026-58187 [HIGH] CWE-787 CVE-2026-58187: The Apache Traffic Server multiplexer plugin overruns its chunk-decode buffer on upstream input, ena
The Apache Traffic Server multiplexer plugin overruns its chunk-decode buffer on upstream input, enabling denial of service.
This issue affects Apache Traffic Server: from 8.0.0 through 8.1.11, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3.
Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.
nvd
CVE-2017-5660P3HIGHCVSS 8.6≤ 6.2.0v6.2.1+2 more2018-02-27
CVE-2017-5660 [HIGH] CWE-20 CVE-2017-5660: There is a vulnerability in Apache Traffic Server (ATS) 6.2.0 and prior and 7.0.0 and prior with the
There is a vulnerability in Apache Traffic Server (ATS) 6.2.0 and prior and 7.0.0 and prior with the Host header and line folding. This can have issues when interacting with upstream proxies and the wrong host being used.
nvd
CVE-2022-28129P3HIGHCVSS 7.5≥ 8.0.0, ≤ 8.1.4≥ 9.0.0, ≤ 9.1.22022-08-10
CVE-2022-28129 [HIGH] CWE-20 CVE-2022-28129: Improper Input Validation vulnerability in HTTP/1.1 header parsing of Apache Traffic Server allows a
Improper Input Validation vulnerability in HTTP/1.1 header parsing of Apache Traffic Server allows an attacker to send invalid headers. This issue affects Apache Traffic Server 8.0.0 to 9.1.2.
nvd
CVE-2022-31780P3HIGHCVSS 7.5≥ 8.0.0, ≤ 8.1.4≥ 9.0.0, ≤ 9.1.22022-08-10
CVE-2022-31780 [HIGH] CWE-20 CVE-2022-31780: Improper Input Validation vulnerability in HTTP/2 frame handling of Apache Traffic Server allows an
Improper Input Validation vulnerability in HTTP/2 frame handling of Apache Traffic Server allows an attacker to smuggle requests. This issue affects Apache Traffic Server 8.0.0 to 9.1.2.
nvd
CVE-2020-17508P3HIGHCVSS 7.5≥ 6.0.0, ≤ 6.2.3≥ 7.0.0, ≤ 7.1.11+1 more2021-01-11
CVE-2020-17508 [HIGH] CVE-2020-17508: The ATS ESI plugin has a memory disclosure vulnerability. If you are running the plugin please upgra
The ATS ESI plugin has a memory disclosure vulnerability. If you are running the plugin please upgrade. Apache Traffic Server versions 7.0.0 to 7.1.11 and 8.0.0 to 8.1.0 are affected.
nvd
CVE-2023-30631P3HIGHCVSS 7.5≥ 8.0.0, < 8.1.7≥ 9.0.0, < 9.2.12023-06-14
CVE-2023-30631 [HIGH] CWE-20 CVE-2023-30631: Improper Input Validation vulnerability in Apache Software Foundation Apache Traffic Server. The co
Improper Input Validation vulnerability in Apache Software Foundation Apache Traffic Server. The configuration option proxy.config.http.push_method_enabled didn't function. However, by default the PUSH method is blocked in the ip_allow configuration file.This issue affects Apache Traffic Server: from 8.0.0 through 9.2.0.
8.x users should upgrade to 8.1
nvd
CVE-2021-44040P3HIGHCVSS 7.5≥ 8.0.0, ≤ 8.1.3≥ 9.0.0, ≤ 9.1.12022-03-23
CVE-2021-44040 [HIGH] CWE-20 CVE-2021-44040: Improper Input Validation vulnerability in request line parsing of Apache Traffic Server allows an a
Improper Input Validation vulnerability in request line parsing of Apache Traffic Server allows an attacker to send invalid requests. This issue affects Apache Traffic Server 8.0.0 to 8.1.3 and 9.0.0 to 9.1.1.
nvd
CVE-2018-8022P3HIGHCVSS 7.5≥ 6.0.0, ≤ 6.2.22018-08-29
CVE-2018-8022 [HIGH] CWE-20 CVE-2018-8022: A carefully crafted invalid TLS handshake can cause Apache Traffic Server (ATS) to segfault. This af
A carefully crafted invalid TLS handshake can cause Apache Traffic Server (ATS) to segfault. This affects version 6.2.2. To resolve this issue users running 6.2.2 should upgrade to 6.2.3 or later versions.
nvd
CVE-2023-38522P3HIGHCVSS 7.5≥ 8.0.0, < 8.1.11≥ 9.0.0, < 9.2.52024-07-26
CVE-2023-38522 [HIGH] CWE-444 CVE-2023-38522: Apache Traffic Server accepts characters that are not allowed for HTTP field names and forwards malf
Apache Traffic Server accepts characters that are not allowed for HTTP field names and forwards malformed requests to origin servers. This can be utilized for request smuggling and may also lead cache poisoning if the origin servers are vulnerable.
This issue affects Apache Traffic Server: from 8.0.0 through 8.1.10, from 9.0.0 through 9.2.4.
Users a
nvd
CVE-2024-35161P3HIGHCVSS 7.5≥ 8.0.0, < 8.1.11≥ 9.0.0, < 9.2.52024-07-26
CVE-2024-35161 [HIGH] CWE-444 CVE-2024-35161: Apache Traffic Server forwards malformed HTTP chunked trailer section to origin servers. This can be
Apache Traffic Server forwards malformed HTTP chunked trailer section to origin servers. This can be utilized for request smuggling and may also lead cache poisoning if the origin servers are vulnerable.
This issue affects Apache Traffic Server: from 8.0.0 through 8.1.10, from 9.0.0 through 9.2.4.
Users can set a new setting (proxy.config.http.drop_
nvd
CVE-2024-38479P3HIGHCVSS 7.5≥ 8.0.0, ≤ 8.1.11≥ 9.0.0, < 9.2.62024-11-14
CVE-2024-38479 [HIGH] CWE-20 CVE-2024-38479: Improper Input Validation vulnerability in Apache Traffic Server. This issue affects Apache Traffic
Improper Input Validation vulnerability in Apache Traffic Server.
This issue affects Apache Traffic Server: from 8.0.0 through 8.1.11, from 9.0.0 through 9.2.5.
Users are recommended to upgrade to version 9.2.6, which fixes the issue, or 10.0.2, which does not have the issue.
nvd
CVE-2021-37149P3HIGHCVSS 7.5≥ 8.0.0, ≤ 8.1.2≥ 9.0.0, ≤ 9.1.02021-11-03
CVE-2021-37149 [HIGH] CWE-20 CVE-2021-37149: Improper Input Validation vulnerability in header parsing of Apache Traffic Server allows an attacke
Improper Input Validation vulnerability in header parsing of Apache Traffic Server allows an attacker to smuggle requests. This issue affects Apache Traffic Server 8.0.0 to 8.1.2 and 9.0.0 to 9.1.0.
nvd
CVE-2021-37148P3HIGHCVSS 7.5≥ 8.0.0, ≤ 8.1.2≥ 9.0.0, ≤ 9.0.12021-11-03
CVE-2021-37148 [HIGH] CWE-20 CVE-2021-37148: Improper input validation vulnerability in header parsing of Apache Traffic Server allows an attacke
Improper input validation vulnerability in header parsing of Apache Traffic Server allows an attacker to smuggle requests. This issue affects Apache Traffic Server 8.0.0 to 8.1.2 and 9.0.0 to 9.0.1.
nvd
CVE-2021-37147P3HIGHCVSS 7.5≥ 8.0.0, ≤ 8.1.2≥ 9.0.0, ≤ 9.1.02021-11-03
CVE-2021-37147 [HIGH] CWE-20 CVE-2021-37147: Improper input validation vulnerability in header parsing of Apache Traffic Server allows an attacke
Improper input validation vulnerability in header parsing of Apache Traffic Server allows an attacker to smuggle requests. This issue affects Apache Traffic Server 8.0.0 to 8.1.2 and 9.0.0 to 9.1.0.
nvd
CVE-2015-5168P3CRITICALCVSS 9.8v5.3.0v5.3.12017-09-13
CVE-2015-5168 [CRITICAL] CVE-2015-5168: Unspecified vulnerability in the HTTP/2 experimental feature in Apache Traffic Server 5.3.x before 5
Unspecified vulnerability in the HTTP/2 experimental feature in Apache Traffic Server 5.3.x before 5.3.2 has unknown impact and attack vectors, a different vulnerability than CVE-2015-5206.
nvd
CVE-2015-5206P3CRITICALCVSS 9.8v5.3.0v5.3.12017-09-13
CVE-2015-5206 [CRITICAL] CVE-2015-5206: Unspecified vulnerability in the HTTP/2 experimental feature in Apache Traffic Server before 5.3.x b
Unspecified vulnerability in the HTTP/2 experimental feature in Apache Traffic Server before 5.3.x before 5.3.2 has unknown impact and attack vectors, a different vulnerability than CVE-2015-5168.
nvd
CVE-2021-32565P3HIGHCVSS 7.5≥ 7.0.0, ≤ 7.1.12≥ 8.0.0, ≤ 8.1.1+1 more2021-06-29
CVE-2021-32565 [HIGH] CWE-444 CVE-2021-32565: Invalid values in the Content-Length header sent to Apache Traffic Server allows an attacker to smug
Invalid values in the Content-Length header sent to Apache Traffic Server allows an attacker to smuggle requests. This issue affects Apache Traffic Server 7.0.0 to 7.1.12, 8.0.0 to 8.1.1, 9.0.0 to 9.0.1.
nvd
CVE-2022-31778P3HIGHCVSS 7.5≥ 8.0.0, ≤ 8.1.4≥ 9.0.0, ≤ 9.1.22022-08-10
CVE-2022-31778 [HIGH] CWE-20 CVE-2022-31778: Improper Input Validation vulnerability in handling the Transfer-Encoding header of Apache Traffic S
Improper Input Validation vulnerability in handling the Transfer-Encoding header of Apache Traffic Server allows an attacker to poison the cache. This issue affects Apache Traffic Server 8.0.0 to 9.0.2.
nvd
CVE-2025-49763P3HIGHCVSS 7.5≥ 9.0.0, < 9.2.11≥ 10.0.0, < 10.0.62025-06-19
CVE-2025-49763 [HIGH] CWE-400 CVE-2025-49763: ESI plugin does not have the limit for maximum inclusion depth, and that allows excessive memory con
ESI plugin does not have the limit for maximum inclusion depth, and that allows excessive memory consumption if malicious instructions are inserted.
Users can use a new setting for the plugin (--max-inclusion-depth) to limit it.
This issue affects Apache Traffic Server: from 10.0.0 through 10.0.5, from 9.0.0 through 9.2.10.
Users are recommended to
nvd