cbcvebase.

Apache Software Foundation Apache Traffic Server vulnerabilities

96 known vulnerabilities affecting apache_software_foundation/apache_traffic_server.

Total CVEs
96
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL15HIGH63MEDIUM18

Vulnerabilities

Page 2 of 5
CVE-2026-58159P3HIGHCVSS 8.2≥ 8.0.0, ≤ 8.1.11≥ 9.0.0, ≤ 9.2.14+1 more2026-07-29
CVE-2026-58159 [HIGH] CWE-863 CVE-2026-58159: Apache Traffic Server can bypass IP access controls on UDS listeners and through ACL matching errors Apache Traffic Server can bypass IP access controls on UDS listeners and through ACL matching errors. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.11, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.
nvd
CVE-2026-58153P3HIGHCVSS 8.3≥ 10.0.0, ≤ 10.1.32026-07-29
CVE-2026-58153 [HIGH] CWE-444 CVE-2026-58153: Apache Traffic Server forwards HTTP/2 origin trailers to HTTP/1 clients without proper chunked frami Apache Traffic Server forwards HTTP/2 origin trailers to HTTP/1 clients without proper chunked framing when converting HTTP/2 to HTTP/1. This issue affects Apache Traffic Server: from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.
nvd
CVE-2026-58188P3HIGHCVSS 8.2≥ 8.0.0, ≤ 8.1.11≥ 9.0.0, ≤ 9.2.14+1 more2026-07-29
CVE-2026-58188 [HIGH] CWE-787 CVE-2026-58188: Several Apache Traffic Server experimental plugins have memory-safety and limit-bypass errors. Th Several Apache Traffic Server experimental plugins have memory-safety and limit-bypass errors. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.11, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.
nvd
CVE-2026-58186P3HIGHCVSS 7.5≥ 8.0.0, ≤ 8.1.11≥ 9.0.0, ≤ 9.2.14+1 more2026-07-29
CVE-2026-58186 [HIGH] CWE-20 CVE-2026-58186: The Apache Traffic Server webp_transform plugin can decode unsafely and serve mislabeled, cacheable The Apache Traffic Server webp_transform plugin can decode unsafely and serve mislabeled, cacheable responses. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.11, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.
nvd
CVE-2025-58136P3HIGHCVSS 7.5≥ 10.0.0, ≤ 10.1.1≥ 9.0.0, ≤ 9.2.122026-04-02
CVE-2025-58136 [HIGH] CWE-670 CVE-2025-58136: A bug in POST request handling causes a crash under a certain condition. This issue affects Apache A bug in POST request handling causes a crash under a certain condition. This issue affects Apache Traffic Server: from 10.0.0 through 10.1.1, from 9.0.0 through 9.2.12. Users are recommended to upgrade to version 10.1.2 or 9.2.13, which fix the issue. A workaround for older versions is to set proxy.config.http.request_buffer_enabled to 0 (the defaul
nvd
CVE-2026-58180P3HIGHCVSS 7.5≥ 8.0.0, ≤ 8.1.11≥ 9.0.0, ≤ 9.2.14+1 more2026-07-29
CVE-2026-58180 [HIGH] CWE-121 CVE-2026-58180: The Apache Traffic Server txn_box plugin overflows the stack from attacker-controlled input. This The Apache Traffic Server txn_box plugin overflows the stack from attacker-controlled input. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.11, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.
nvd
CVE-2026-58181P3HIGHCVSS 7.5≥ 8.0.0, ≤ 8.1.11≥ 9.0.0, ≤ 9.2.14+1 more2026-07-29
CVE-2026-58181 [HIGH] CWE-121 CVE-2026-58181: The Apache Traffic Server uri_signing and url_sig plugins can exhaust the stack or crash on attacker The Apache Traffic Server uri_signing and url_sig plugins can exhaust the stack or crash on attacker input. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.11, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.
nvd
CVE-2026-58178P3HIGHCVSS 7.5≥ 8.0.0, ≤ 8.1.11≥ 9.0.0, ≤ 9.2.14+1 more2026-07-29
CVE-2026-58178 [HIGH] CWE-674 CVE-2026-58178: The Apache Traffic Server ESI plugin can recurse without bound and fetch attacker-controlled URLs. The Apache Traffic Server ESI plugin can recurse without bound and fetch attacker-controlled URLs. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.11, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.
nvd
CVE-2018-1318P3HIGHCVSS 7.5v6.0.0 to 6.2.2v7.0.0 to 7.1.32018-08-29
CVE-2018-1318 [HIGH] CWE-20 CVE-2018-1318: Adding method ACLs in remap.config can cause a segfault when the user makes a carefully crafted requ Adding method ACLs in remap.config can cause a segfault when the user makes a carefully crafted request. This affects versions Apache Traffic Server (ATS) 6.0.0 to 6.2.2 and 7.0.0 to 7.1.3. To resolve this issue users running 6.x should upgrade to 6.2.3 or later versions and 7.x users should upgrade to 7.1.4 or later versions.
nvd
CVE-2026-58151P3HIGHCVSS 7.5≥ 8.0.0, ≤ 8.1.11≥ 9.0.0, ≤ 9.2.14+1 more2026-07-29
CVE-2026-58151 [HIGH] CWE-400 CVE-2026-58151: Apache Traffic Server can be crashed or driven to resource exhaustion by abusive HTTP/2 framing and Apache Traffic Server can be crashed or driven to resource exhaustion by abusive HTTP/2 framing and flow-control. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.11, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.
nvd
CVE-2026-65324P3HIGHCVSS 7.5≥ 8.0.0, ≤ 8.1.11≥ 9.0.0, ≤ 9.2.14+1 more2026-07-29
CVE-2026-65324 [HIGH] CWE-400 CVE-2026-65324: Apache Traffic Server drops the per-stream buffer cap when dechunking HTTP/2 or HTTP/3 responses, le Apache Traffic Server drops the per-stream buffer cap when dechunking HTTP/2 or HTTP/3 responses, letting a slow client exhaust server memory. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.11, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.
nvd
CVE-2026-58183P3HIGHCVSS 7.5≥ 8.0.0, ≤ 8.1.11≥ 9.0.0, ≤ 9.2.14+1 more2026-07-29
CVE-2026-58183 [HIGH] CWE-20 CVE-2026-58183: The Apache Traffic Server prefetch plugin can crash when processing attacker-influenced input. Th The Apache Traffic Server prefetch plugin can crash when processing attacker-influenced input. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.11, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.
nvd
CVE-2025-65114P3HIGHCVSS 7.5≥ 9.0.0, ≤ 9.2.12≥ 10.0.0, ≤ 10.1.12026-04-02
CVE-2025-65114 [HIGH] CWE-444 CVE-2025-65114: Apache Traffic Server allows request smuggling if chunked messages are malformed. This issue affec Apache Traffic Server allows request smuggling if chunked messages are malformed. This issue affects Apache Traffic Server: from 9.0.0 through 9.2.12, from 10.0.0 through 10.1.1. Users are recommended to upgrade to version 9.2.13 or 10.1.2, which fix the issue.
nvd
CVE-2026-59173P3HIGHCVSS 7.5≥ 9.0.0, ≤ 9.2.13≥ 10.0.0, ≤ 10.1.22026-07-18
CVE-2026-59173 [HIGH] CWE-400 CVE-2026-59173: Uncontrolled Resource Consumption vulnerability in Apache Traffic Server. This issue affects Apache Uncontrolled Resource Consumption vulnerability in Apache Traffic Server. This issue affects Apache Traffic Server: from 9.0.0 through 9.1.13, from 10.0.0 through 10.1.2. Users are recommended to upgrade to version 9.1.14 or 10.1.3, which fixes the issue.
nvd
CVE-2026-58161P3HIGHCVSS 7.5≥ 8.0.0, ≤ 8.1.11≥ 9.0.0, ≤ 9.2.14+1 more2026-07-29
CVE-2026-58161 [HIGH] CWE-476 CVE-2026-58161: Apache Traffic Server can crash from null dereferences and dangling references in TLS and SNI handli Apache Traffic Server can crash from null dereferences and dangling references in TLS and SNI handling. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.11, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.
nvd
CVE-2026-58164P3HIGHCVSS 7.5≥ 8.0.0, ≤ 8.1.11≥ 9.0.0, ≤ 9.2.14+1 more2026-07-29
CVE-2026-58164 [HIGH] CWE-416 CVE-2026-58164: Apache Traffic Server has use-after-free and time-of-check/time-of-use errors in remap configuration Apache Traffic Server has use-after-free and time-of-check/time-of-use errors in remap configuration handling. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.11, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.
nvd
CVE-2026-58189P3HIGHCVSS 7.5≥ 8.0.0, ≤ 8.1.11≥ 9.0.0, ≤ 9.2.14+1 more2026-07-29
CVE-2026-58189 [HIGH] CWE-918 CVE-2026-58189: Apache Traffic Server allows redirect-limit bypass when plugins reset the retry counter, enabling SS Apache Traffic Server allows redirect-limit bypass when plugins reset the retry counter, enabling SSRF amplification. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.11, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.
nvd
CVE-2026-58184P3HIGHCVSS 7.5≥ 8.0.0, ≤ 8.1.11≥ 9.0.0, ≤ 9.2.14+1 more2026-07-29
CVE-2026-58184 [HIGH] CWE-787 CVE-2026-58184: The Apache Traffic Server header_rewrite plugin can crash or corrupt memory during cookie operations The Apache Traffic Server header_rewrite plugin can crash or corrupt memory during cookie operations and CIDR condition matching. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.11, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.
nvd
CVE-2021-44759P3HIGHCVSS 8.1v8.0.0 to 8.1.02022-03-23
CVE-2021-44759 [HIGH] CWE-287 CVE-2021-44759: Improper Authentication vulnerability in TLS origin validation of Apache Traffic Server allows an at Improper Authentication vulnerability in TLS origin validation of Apache Traffic Server allows an attacker to create a man in the middle attack. This issue affects Apache Traffic Server 8.0.0 to 8.1.0.
nvd
CVE-2022-25763P3HIGHCVSS 7.5v8.0.0 to 9.1.22022-08-10
CVE-2022-25763 [HIGH] CWE-444 CVE-2022-25763: Improper Input Validation vulnerability in HTTP/2 request validation of Apache Traffic Server allows Improper Input Validation vulnerability in HTTP/2 request validation of Apache Traffic Server allows an attacker to create smuggle or cache poison attacks. This issue affects Apache Traffic Server 8.0.0 to 9.1.2.
nvd
Apache Software Foundation Apache Traffic Server vulnerabilities | cvebase