Apache Software Foundation Apache Traffic Server vulnerabilities
57 known vulnerabilities affecting apache_software_foundation/apache_traffic_server.
Total CVEs
57
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL4HIGH44MEDIUM9
Vulnerabilities
Page 1 of 3
CVE-2024-31309P2HIGHCVSS 7.5≥ 8.0.0, ≤ 8.1.9≥ 9.0.0, ≤ 9.2.32024-04-10
CVE-2024-31309 [HIGH] CWE-20 CVE-2024-31309: HTTP/2 CONTINUATION DoS attack can cause Apache Traffic Server to consume more resources on the serv
HTTP/2 CONTINUATION DoS attack can cause Apache Traffic Server to consume more resources on the server. Version from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.3 are affected.
Users can set a new setting (proxy.config.http2.max_continuation_frames_per_minute) to limit the number of CONTINUATION frames per minute. ATS does have a fixed amount of memor
nvd
CVE-2023-39456P3HIGHCVSS 7.5≥ 9.0.0, ≤ 9.2.22023-10-17
CVE-2023-39456 [HIGH] CWE-20 CVE-2023-39456: Improper Input Validation vulnerability in Apache Traffic Server with malformed HTTP/2 frames.This i
Improper Input Validation vulnerability in Apache Traffic Server with malformed HTTP/2 frames.This issue affects Apache Traffic Server: from 9.0.0 through 9.2.2.
Users are recommended to upgrade to version 9.2.3, which fixes the issue.
nvd
CVE-2021-35474P3CRITICALCVSS 9.8vApache Traffic Server 7.0.0 to 7.1.12, 8.0.0 to 8.1.1, 9.0.0 to 9.0.12021-06-30
CVE-2021-35474 [CRITICAL] CWE-121 CVE-2021-35474: Stack-based Buffer Overflow vulnerability in cachekey plugin of Apache Traffic Server. This issue af
Stack-based Buffer Overflow vulnerability in cachekey plugin of Apache Traffic Server. This issue affects Apache Traffic Server 7.0.0 to 7.1.12, 8.0.0 to 8.1.1, 9.0.0 to 9.0.1.
nvd
CVE-2021-43082P3CRITICALCVSS 9.8v9.1.02021-11-03
CVE-2021-43082 [CRITICAL] CWE-120 CVE-2021-43082: Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in the stats-ov
Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in the stats-over-http plugin of Apache Traffic Server allows an attacker to overwrite memory. This issue affects Apache Traffic Server 9.1.0.
nvd
CVE-2024-50306P3CRITICALCVSS 9.1≥ 9.2.0, ≤ 9.2.5≥ 10.0.0, ≤ 10.0.12024-11-14
CVE-2024-50306 [CRITICAL] CWE-252 CVE-2024-50306: Unchecked return value can allow Apache Traffic Server to retain privileges on startup. This issue
Unchecked return value can allow Apache Traffic Server to retain privileges on startup.
This issue affects Apache Traffic Server: from 9.2.0 through 9.2.5, from 10.0.0 through 10.0.1.
Users are recommended to upgrade to version 9.2.6 or 10.0.2, which fixes the issue.
nvd
CVE-2023-33934P3CRITICALCVSS 9.1≤ 9.2.12023-08-09
CVE-2023-33934 [CRITICAL] CWE-444 CVE-2023-33934: Improper Input Validation vulnerability in Apache Software Foundation Apache Traffic Server.This iss
Improper Input Validation vulnerability in Apache Software Foundation Apache Traffic Server.This issue affects Apache Traffic Server: through 9.2.1.
nvd
CVE-2018-1318P3HIGHCVSS 7.5v6.0.0 to 6.2.2v7.0.0 to 7.1.32018-08-29
CVE-2018-1318 [HIGH] CWE-20 CVE-2018-1318: Adding method ACLs in remap.config can cause a segfault when the user makes a carefully crafted requ
Adding method ACLs in remap.config can cause a segfault when the user makes a carefully crafted request. This affects versions Apache Traffic Server (ATS) 6.0.0 to 6.2.2 and 7.0.0 to 7.1.3. To resolve this issue users running 6.x should upgrade to 6.2.3 or later versions and 7.x users should upgrade to 7.1.4 or later versions.
nvd
CVE-2025-58136P3HIGHCVSS 7.5≥ 10.0.0, ≤ 10.1.1≥ 9.0.0, ≤ 9.2.122026-04-02
CVE-2025-58136 [HIGH] CWE-670 CVE-2025-58136: A bug in POST request handling causes a crash under a certain condition. This issue affects Apache
A bug in POST request handling causes a crash under a certain condition.
This issue affects Apache Traffic Server: from 10.0.0 through 10.1.1, from 9.0.0 through 9.2.12.
Users are recommended to upgrade to version 10.1.2 or 9.2.13, which fix the issue.
A workaround for older versions is to set proxy.config.http.request_buffer_enabled to 0 (the defaul
nvd
CVE-2025-65114P3HIGHCVSS 7.5≥ 9.0.0, ≤ 9.2.12≥ 10.0.0, ≤ 10.1.12026-04-02
CVE-2025-65114 [HIGH] CWE-444 CVE-2025-65114: Apache Traffic Server allows request smuggling if chunked messages are malformed. This issue affec
Apache Traffic Server allows request smuggling if chunked messages are malformed.
This issue affects Apache Traffic Server: from 9.0.0 through 9.2.12, from 10.0.0 through 10.1.1.
Users are recommended to upgrade to version 9.2.13 or 10.1.2, which fix the issue.
nvd
CVE-2026-59173P3HIGHCVSS 7.5≥ 9.0.0, ≤ 9.2.13≥ 10.0.0, ≤ 10.1.22026-07-18
CVE-2026-59173 [HIGH] CWE-400 CVE-2026-59173: Uncontrolled Resource Consumption vulnerability in Apache Traffic Server. This issue affects Apache
Uncontrolled Resource Consumption vulnerability in Apache Traffic Server.
This issue affects Apache Traffic Server: from 9.0.0 through 9.1.13, from 10.0.0 through 10.1.2.
Users are recommended to upgrade to version 9.1.14 or 10.1.3, which fixes the issue.
nvd
CVE-2024-35296P3HIGHCVSS 8.2≥ 8.0.0, ≤ 8.1.10≥ 9.0.0, ≤ 9.2.42024-07-26
CVE-2024-35296 [HIGH] CWE-20 CVE-2024-35296: Invalid Accept-Encoding header can cause Apache Traffic Server to fail cache lookup and force forwar
Invalid Accept-Encoding header can cause Apache Traffic Server to fail cache lookup and force forwarding requests.
This issue affects Apache Traffic Server: from 8.0.0 through 8.1.10, from 9.0.0 through 9.2.4.
Users are recommended to upgrade to version 8.1.11 or 9.2.5, which fixes the issue.
nvd
CVE-2022-25763P3HIGHCVSS 7.5v8.0.0 to 9.1.22022-08-10
CVE-2022-25763 [HIGH] CWE-444 CVE-2022-25763: Improper Input Validation vulnerability in HTTP/2 request validation of Apache Traffic Server allows
Improper Input Validation vulnerability in HTTP/2 request validation of Apache Traffic Server allows an attacker to create smuggle or cache poison attacks. This issue affects Apache Traffic Server 8.0.0 to 9.1.2.
nvd
CVE-2024-53868P3HIGHCVSS 7.5≥ 9.2.0, ≤ 9.2.9≥ 10.0.0, ≤ 10.0.42025-04-03
CVE-2024-53868 [HIGH] CWE-444 CVE-2024-53868: Apache Traffic Server allows request smuggling if chunked messages are malformed. This issue a
Apache Traffic Server allows request smuggling if chunked messages are malformed.
This issue affects Apache Traffic Server: from 9.2.0 through 9.2.9, from 10.0.0 through 10.0.4.
Users are recommended to upgrade to version 9.2.10 or 10.0.5, which fixes the issue.
nvd
CVE-2025-31698P3HIGHCVSS 7.5≥ 10.0.0, ≤ 10.0.6≥ 9.0.0, ≤ 9.2.102025-06-19
CVE-2025-31698 [HIGH] CWE-284 CVE-2025-31698: ACL configured in ip_allow.config or remap.config does not use IP addresses that are provided by PRO
ACL configured in ip_allow.config or remap.config does not use IP addresses that are provided by PROXY protocol.
Users can use a new setting (proxy.config.acl.subjects) to choose which IP addresses to use for the ACL if Apache Traffic Server is configured to accept PROXY protocol.
This issue affects undefined: from 10.0.0 through 10.0.6, from 9.0.0 t
nvd
CVE-2021-38161P3HIGHCVSS 8.1v8.0.0 to 8.0.82021-11-03
CVE-2021-38161 [HIGH] CWE-287 CVE-2021-38161: Improper Authentication vulnerability in TLS origin verification of Apache Traffic Server allows for
Improper Authentication vulnerability in TLS origin verification of Apache Traffic Server allows for man in the middle attacks. This issue affects Apache Traffic Server 8.0.0 to 8.0.8.
nvd
CVE-2021-44759P3HIGHCVSS 8.1v8.0.0 to 8.1.02022-03-23
CVE-2021-44759 [HIGH] CWE-287 CVE-2021-44759: Improper Authentication vulnerability in TLS origin validation of Apache Traffic Server allows an at
Improper Authentication vulnerability in TLS origin validation of Apache Traffic Server allows an attacker to create a man in the middle attack. This issue affects Apache Traffic Server 8.0.0 to 8.1.0.
nvd
CVE-2021-44040P3HIGHCVSS 7.5v8.0.0 to 8.1.3 and 9.0.0 to 9.1.12022-03-23
CVE-2021-44040 [HIGH] CWE-20 CVE-2021-44040: Improper Input Validation vulnerability in request line parsing of Apache Traffic Server allows an a
Improper Input Validation vulnerability in request line parsing of Apache Traffic Server allows an attacker to send invalid requests. This issue affects Apache Traffic Server 8.0.0 to 8.1.3 and 9.0.0 to 9.1.1.
nvd
CVE-2022-31779P3HIGHCVSS 7.5v8.0.0 to 9.1.22022-08-10
CVE-2022-31779 [HIGH] CWE-20 CVE-2022-31779: Improper Input Validation vulnerability in HTTP/2 header parsing of Apache Traffic Server allows an
Improper Input Validation vulnerability in HTTP/2 header parsing of Apache Traffic Server allows an attacker to smuggle requests. This issue affects Apache Traffic Server 8.0.0 to 9.1.2.
nvd
CVE-2021-37150P3HIGHCVSS 7.5v8.0.0 to 9.1.22022-08-10
CVE-2021-37150 [HIGH] CWE-20 CVE-2021-37150: Improper Input Validation vulnerability in header parsing of Apache Traffic Server allows an attacke
Improper Input Validation vulnerability in header parsing of Apache Traffic Server allows an attacker to request secure resources. This issue affects Apache Traffic Server 8.0.0 to 9.1.2.
nvd
CVE-2017-5660P3HIGHCVSS 8.6v6.2.0 and priorv7.0.0 and prior2018-02-27
CVE-2017-5660 [HIGH] CWE-20 CVE-2017-5660: There is a vulnerability in Apache Traffic Server (ATS) 6.2.0 and prior and 7.0.0 and prior with the
There is a vulnerability in Apache Traffic Server (ATS) 6.2.0 and prior and 7.0.0 and prior with the Host header and line folding. This can have issues when interacting with upstream proxies and the wrong host being used.
nvd
1 / 3Next →