cbcvebase.

Apache Software Foundation Apache Traffic Server vulnerabilities

96 known vulnerabilities affecting apache_software_foundation/apache_traffic_server.

Total CVEs
96
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL15HIGH63MEDIUM18

Vulnerabilities

Page 1 of 5
CVE-2024-31309P2HIGHCVSS 7.5≥ 8.0.0, ≤ 8.1.9≥ 9.0.0, ≤ 9.2.32024-04-10
CVE-2024-31309 [HIGH] CWE-20 CVE-2024-31309: HTTP/2 CONTINUATION DoS attack can cause Apache Traffic Server to consume more resources on the serv HTTP/2 CONTINUATION DoS attack can cause Apache Traffic Server to consume more resources on the server. Version from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.3 are affected. Users can set a new setting (proxy.config.http2.max_continuation_frames_per_minute) to limit the number of CONTINUATION frames per minute. ATS does have a fixed amount of memor
nvd
CVE-2026-57834P2CRITICALCVSS 10.0≥ 8.0.0, ≤ 8.1.11≥ 9.0.0, ≤ 9.2.14+1 more2026-07-29
CVE-2026-57834 [CRITICAL] CWE-444 CVE-2026-57834: Apache Traffic Server allows request smuggling if chunked messages are malformed. This issue affe Apache Traffic Server allows request smuggling if chunked messages are malformed. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.11, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.
nvd
CVE-2026-58150P2CRITICALCVSS 10.0≥ 8.0.0, ≤ 8.1.11≥ 9.0.0, ≤ 9.2.14+1 more2026-07-29
CVE-2026-58150 [CRITICAL] CWE-444 CVE-2026-58150: Apache Traffic Server does not reject Transfer-Encoding in HTTP/2 requests, allowing downgrade reque Apache Traffic Server does not reject Transfer-Encoding in HTTP/2 requests, allowing downgrade request smuggling. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.11, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.
nvd
CVE-2026-58162P2CRITICALCVSS 10.0≥ 8.0.0, ≤ 8.1.11≥ 9.0.0, ≤ 9.2.14+1 more2026-07-29
CVE-2026-58162 [CRITICAL] CWE-295 CVE-2026-58162: The Apache Traffic Server certifier plugin generates certificates based on attacker-controlled clien The Apache Traffic Server certifier plugin generates certificates based on attacker-controlled client SNI. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.11, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.
nvd
CVE-2026-58179P2CRITICALCVSS 9.8≥ 8.0.0, ≤ 8.1.11≥ 9.0.0, ≤ 9.2.14+1 more2026-07-29
CVE-2026-58179 [CRITICAL] CWE-121 CVE-2026-58179: The Apache Traffic Server regex_remap plugin overflows the stack and integers from substitution inpu The Apache Traffic Server regex_remap plugin overflows the stack and integers from substitution input. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.11, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.
nvd
CVE-2023-39456P3HIGHCVSS 7.5≥ 9.0.0, ≤ 9.2.22023-10-17
CVE-2023-39456 [HIGH] CWE-20 CVE-2023-39456: Improper Input Validation vulnerability in Apache Traffic Server with malformed HTTP/2 frames.This i Improper Input Validation vulnerability in Apache Traffic Server with malformed HTTP/2 frames.This issue affects Apache Traffic Server: from 9.0.0 through 9.2.2. Users are recommended to upgrade to version 9.2.3, which fixes the issue.
nvd
CVE-2026-58185P2CRITICALCVSS 9.8≥ 8.0.0, ≤ 8.1.11≥ 9.0.0, ≤ 9.2.14+1 more2026-07-29
CVE-2026-58185 [CRITICAL] CWE-416 CVE-2026-58185: The Apache Traffic Server intercept plugin has a use-after-free. This issue affects Apache Traffi The Apache Traffic Server intercept plugin has a use-after-free. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.11, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.
nvd
CVE-2026-58155P2CRITICALCVSS 9.3≥ 8.0.0, ≤ 8.1.11≥ 9.0.0, ≤ 9.2.14+1 more2026-07-29
CVE-2026-58155 [CRITICAL] CWE-444 CVE-2026-58155: Apache Traffic Server truncates over-long header names, allowing header aliasing, request smuggling, Apache Traffic Server truncates over-long header names, allowing header aliasing, request smuggling, and policy bypass. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.11, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.
nvd
CVE-2026-58177P2CRITICALCVSS 9.8≥ 10.0.0, ≤ 10.1.32026-07-29
CVE-2026-58177 [CRITICAL] CWE-787 CVE-2026-58177: The Apache Traffic Server Cripts framework has out-of-bounds writes, path traversal, and use-after-f The Apache Traffic Server Cripts framework has out-of-bounds writes, path traversal, and use-after-free errors. This issue affects Apache Traffic Server: from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 10.1.4, which fix the issue.
nvd
CVE-2026-58163P2CRITICALCVSS 9.1≥ 8.0.0, ≤ 8.1.11≥ 9.0.0, ≤ 9.2.14+1 more2026-07-29
CVE-2026-58163 [CRITICAL] CWE-502 CVE-2026-58163: Apache Traffic Server mishandles on-disk cache fields and object lifetimes, corrupting state or cras Apache Traffic Server mishandles on-disk cache fields and object lifetimes, corrupting state or crashing. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.11, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.
nvd
CVE-2026-33267P2CRITICALCVSS 9.1≥ 9.2.0, ≤ 9.2.14≥ 10.1.0, ≤ 10.1.32026-07-29
CVE-2026-33267 [CRITICAL] CWE-20 CVE-2026-33267: Improper Input Validation vulnerability in Apache Traffic Server. This issue affects Apache Traffic Improper Input Validation vulnerability in Apache Traffic Server. This issue affects Apache Traffic Server: from 9.2.0 through 9.2.14, from 10.1.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fixes the issue.
nvd
CVE-2026-102795P2CRITICALCVSS 9.3≥ 9.0.0, ≤ 9.2.14≥ 10.0.0, ≤ 10.1.32026-10-02
CVE-2026-102795 [CRITICAL] CWE-284 CVE-2026-102795: Improper Access Control vulnerability in Apache Traffic Server. This issue affects Apache Traffic Improper Access Control vulnerability in Apache Traffic Server. This issue affects Apache Traffic Server: from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fixes the issue. This CVE supersedes CVE-2026-41920, whose record listed the affected 9.x versions as 9.0.0 through
nvd
CVE-2026-58157P2HIGHCVSS 8.7≥ 8.0.0, ≤ 8.1.11≥ 9.0.0, ≤ 9.2.14+1 more2026-07-29
CVE-2026-58157 [HIGH] CWE-200 CVE-2026-58157: Apache Traffic Server can reuse server sessions and tunnels improperly, exposing data across client Apache Traffic Server can reuse server sessions and tunnels improperly, exposing data across client connections. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.11, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.
nvd
CVE-2026-41920P3CRITICALCVSS 9.3≥ 9.0.0, ≤ 9.1.14≥ 10.0.0, ≤ 10.1.32026-07-29
CVE-2026-41920 [CRITICAL] CWE-284 CVE-2026-41920: Improper Access Control vulnerability in Apache Traffic Server. This issue affects Apache Traffic S Improper Access Control vulnerability in Apache Traffic Server. This issue affects Apache Traffic Server: from 9.0.0 through 9.1.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.1.15 or 10.1.4, which fixes the issue.
nvd
CVE-2026-58154P3HIGHCVSS 8.9≥ 8.0.0, ≤ 8.1.11≥ 9.0.0, ≤ 9.2.14+1 more2026-07-29
CVE-2026-58154 [HIGH] CWE-787 CVE-2026-58154: Apache Traffic Server can write out of bounds or overflow integers while parsing MIME and HTTP heade Apache Traffic Server can write out of bounds or overflow integers while parsing MIME and HTTP headers. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.11, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.
nvd
CVE-2021-35474P3CRITICALCVSS 9.8vApache Traffic Server 7.0.0 to 7.1.12, 8.0.0 to 8.1.1, 9.0.0 to 9.0.12021-06-30
CVE-2021-35474 [CRITICAL] CWE-121 CVE-2021-35474: Stack-based Buffer Overflow vulnerability in cachekey plugin of Apache Traffic Server. This issue af Stack-based Buffer Overflow vulnerability in cachekey plugin of Apache Traffic Server. This issue affects Apache Traffic Server 7.0.0 to 7.1.12, 8.0.0 to 8.1.1, 9.0.0 to 9.0.1.
nvd
CVE-2021-43082P3CRITICALCVSS 9.8v9.1.02021-11-03
CVE-2021-43082 [CRITICAL] CWE-120 CVE-2021-43082: Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in the stats-ov Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in the stats-over-http plugin of Apache Traffic Server allows an attacker to overwrite memory. This issue affects Apache Traffic Server 9.1.0.
nvd
CVE-2026-58182P3HIGHCVSS 8.6≥ 8.0.0, ≤ 8.1.11≥ 9.0.0, ≤ 9.2.14+1 more2026-07-29
CVE-2026-58182 [HIGH] CWE-400 CVE-2026-58182: The Apache Traffic Server ts_lua plugin mishandles initialization, transform context, and per-instan The Apache Traffic Server ts_lua plugin mishandles initialization, transform context, and per-instance state. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.11, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.
nvd
CVE-2024-50306P3CRITICALCVSS 9.1≥ 9.2.0, ≤ 9.2.5≥ 10.0.0, ≤ 10.0.12024-11-14
CVE-2024-50306 [CRITICAL] CWE-252 CVE-2024-50306: Unchecked return value can allow Apache Traffic Server to retain privileges on startup. This issue Unchecked return value can allow Apache Traffic Server to retain privileges on startup. This issue affects Apache Traffic Server: from 9.2.0 through 9.2.5, from 10.0.0 through 10.0.1. Users are recommended to upgrade to version 9.2.6 or 10.0.2, which fixes the issue.
nvd
CVE-2023-33934P3CRITICALCVSS 9.1≤ 9.2.12023-08-09
CVE-2023-33934 [CRITICAL] CWE-444 CVE-2023-33934: Improper Input Validation vulnerability in Apache Software Foundation Apache Traffic Server.This iss Improper Input Validation vulnerability in Apache Software Foundation Apache Traffic Server.This issue affects Apache Traffic Server: through 9.2.1.
nvd
Apache Software Foundation Apache Traffic Server vulnerabilities | cvebase