Apache Software Foundation Apache Traffic Server vulnerabilities
57 known vulnerabilities affecting apache_software_foundation/apache_traffic_server.
Total CVEs
57
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL4HIGH44MEDIUM9
Vulnerabilities
Page 3 of 3
CVE-2018-11783P3HIGHCVSS 7.5vApache Traffic Server 6.0.0 to 6.0.3, 7.0.0 to 7.1.5, 8.0.0 to 8.0.12019-03-07
CVE-2018-11783 [HIGH] CWE-200 CVE-2018-11783: sslheaders plugin extracts information from the client certificate and sets headers in the request b
sslheaders plugin extracts information from the client certificate and sets headers in the request based on the configuration of the plugin. The plugin doesn't strip the headers from the request in some scenarios. This problem was discovered in versions 6.0.0 to 6.0.3, 7.0.0 to 7.1.5, and 8.0.0 to 8.0.1.
nvd
CVE-2022-47185P3HIGHCVSS 7.5≤ 9.2.12023-08-09
CVE-2022-47185 [HIGH] CWE-20 CVE-2022-47185: Improper input validation vulnerability on the range header in Apache Software Foundation Apache Tra
Improper input validation vulnerability on the range header in Apache Software Foundation Apache Traffic Server.This issue affects Apache Traffic Server: through 9.2.1.
nvd
CVE-2022-32749P3HIGHCVSS 7.5≥ 8.0.0, ≤ 9.1.32022-12-19
CVE-2022-32749 [HIGH] CWE-754 CVE-2022-32749: Improper Check for Unusual or Exceptional Conditions vulnerability handling requests in Apache Traf
Improper Check for Unusual or Exceptional Conditions vulnerability handling requests in Apache Traffic Server allows an attacker to crash the server under certain conditions.
This issue affects Apache Traffic Server: from 8.0.0 through 9.1.3.
nvd
CVE-2020-9494P3HIGHCVSS 7.5v6.0.0 to 6.2.3v7.0.0 to 7.1.10+1 more2020-06-24
CVE-2020-9494 [HIGH] CWE-770 CVE-2020-9494: Apache Traffic Server 6.0.0 to 6.2.3, 7.0.0 to 7.1.10, and 8.0.0 to 8.0.7 is vulnerable to certain t
Apache Traffic Server 6.0.0 to 6.2.3, 7.0.0 to 7.1.10, and 8.0.0 to 8.0.7 is vulnerable to certain types of HTTP/2 HEADERS frames that can cause the server to allocate a large amount of memory and spin the thread.
nvd
CVE-2018-8004P3MEDIUMCVSS 6.5v6.0.0 to 6.2.2v7.0.0 to 7.1.32018-08-29
CVE-2018-8004 [MEDIUM] CWE-444 CVE-2018-8004: There are multiple HTTP smuggling and cache poisoning issues when clients making malicious requests
There are multiple HTTP smuggling and cache poisoning issues when clients making malicious requests interact with Apache Traffic Server (ATS). This affects versions 6.0.0 to 6.2.2 and 7.0.0 to 7.1.3. To resolve this issue users running 6.x should upgrade to 6.2.3 or later versions and 7.x users should upgrade to 7.1.4 or later versions.
nvd
CVE-2024-50305P3HIGHCVSS 7.5≥ 9.2.0, ≤ 9.2.52024-11-14
CVE-2024-50305 [HIGH] CWE-20 CVE-2024-50305: Valid Host header field can cause Apache Traffic Server to crash on some platforms. This issue affe
Valid Host header field can cause Apache Traffic Server to crash on some platforms.
This issue affects Apache Traffic Server: from 9.2.0 through 9.2.5.
Users are recommended to upgrade to version 9.2.6, which fixes the issue, or 10.0.2, which does not have the issue.
nvd
CVE-2024-38311P3MEDIUMCVSS 6.3≥ 8.0.0, ≤ 8.1.11≥ 9.0.0, ≤ 9.2.8+1 more2025-03-06
CVE-2024-38311 [MEDIUM] CWE-20 CVE-2024-38311: Improper Input Validation vulnerability in Apache Traffic Server. This issue affects Apache Traffic
Improper Input Validation vulnerability in Apache Traffic Server.
This issue affects Apache Traffic Server: from 8.0.0 through 8.1.11, from 9.0.0 through 9.2.8, from 10.0.0 through 10.0.3.
Users are recommended to upgrade to version 9.2.9 or 10.0.4, which fixes the issue.
nvd
CVE-2024-56195P3MEDIUMCVSS 6.3≥ 9.2.0, ≤ 9.2.8≥ 10.0.0, ≤ 10.0.32025-03-06
CVE-2024-56195 [MEDIUM] CWE-284 CVE-2024-56195: Improper Access Control vulnerability in Apache Traffic Server. This issue affects Apache Traffic S
Improper Access Control vulnerability in Apache Traffic Server.
This issue affects Apache Traffic Server: from 9.2.0 through 9.2.8, from 10.0.0 through 10.0.3.
Users are recommended to upgrade to version 9.2.9 or 10.0.4, which fixes the issue.
nvd
CVE-2024-56196P3MEDIUMCVSS 6.3≥ 10.0.0, ≤ 10.0.32025-03-06
CVE-2024-56196 [MEDIUM] CWE-284 CVE-2024-56196: Improper Access Control vulnerability in Apache Traffic Server. This issue affects Apache Traffic S
Improper Access Control vulnerability in Apache Traffic Server.
This issue affects Apache Traffic Server: from 10.0.0 through 10.0.3.
Users are recommended to upgrade to version 10.0.4, which fixes the issue.
nvd
CVE-2016-5396P3HIGHCVSS 7.5v6.0.0 to 6.2.02017-04-17
CVE-2016-5396 [HIGH] CWE-399 CVE-2016-5396: Apache Traffic Server 6.0.0 to 6.2.0 are affected by an HPACK Bomb Attack.
Apache Traffic Server 6.0.0 to 6.2.0 are affected by an HPACK Bomb Attack.
nvd
CVE-2017-7671P3HIGHCVSS 7.5v5.2.0 to 5.3.2v6.0.0 to 6.2.0+1 more2018-02-27
CVE-2017-7671 [HIGH] CWE-20 CVE-2017-7671: There is a DOS attack vulnerability in Apache Traffic Server (ATS) 5.2.0 to 5.3.2, 6.0.0 to 6.2.0, a
There is a DOS attack vulnerability in Apache Traffic Server (ATS) 5.2.0 to 5.3.2, 6.0.0 to 6.2.0, and 7.0.0 with the TLS handshake. This issue can cause the server to coredump.
nvd
CVE-2018-8040P3MEDIUMCVSS 5.3v6.0.0 to 6.2.2v7.0.0 to 7.1.32018-08-29
CVE-2018-8040 [MEDIUM] CWE-668 CVE-2018-8040: Pages that are rendered using the ESI plugin can have access to the cookie header when the plugin is
Pages that are rendered using the ESI plugin can have access to the cookie header when the plugin is configured not to allow access. This affects Apache Traffic Server (ATS) versions 6.0.0 to 6.2.2 and 7.0.0 to 7.1.3. To resolve this issue users running 6.x should upgrade to 6.2.3 or later versions and 7.x users should upgrade to 7.1.4 or later versio
nvd
CVE-2017-5659P4HIGHCVSS 7.5vAll versions prior to version 6.2.12017-04-17
CVE-2017-5659 [HIGH] CWE-20 CVE-2017-5659: Apache Traffic Server before 6.2.1 generates a coredump when there is a mismatch between content len
Apache Traffic Server before 6.2.1 generates a coredump when there is a mismatch between content length and chunked encoding.
nvd
CVE-2018-8005P4MEDIUMCVSS 5.3v6.0.0 to 6.2.2v7.0.0 to 7.1.32018-08-29
CVE-2018-8005 [MEDIUM] CWE-400 CVE-2018-8005: When there are multiple ranges in a range request, Apache Traffic Server (ATS) will read the entire
When there are multiple ranges in a range request, Apache Traffic Server (ATS) will read the entire object from cache. This can cause performance problems with large objects in cache. This affects versions 6.0.0 to 6.2.2 and 7.0.0 to 7.1.3. To resolve this issue users running 6.x users should upgrade to 6.2.3 or later versions and 7.x users should upgr
nvd
CVE-2022-40743P4MEDIUMCVSS 6.1≥ 9.0.0, ≤ 9.1.32022-12-19
CVE-2022-40743 [MEDIUM] CWE-79 CVE-2022-40743: Improper Input Validation vulnerability for the xdebug plugin in Apache Software Foundation Apache T
Improper Input Validation vulnerability for the xdebug plugin in Apache Software Foundation Apache Traffic Server can lead to cross site scripting and cache poisoning attacks.This issue affects Apache Traffic Server: 9.0.0 to 9.1.3. Users should upgrade to 9.1.4 or later versions.
nvd
CVE-2022-37392P4MEDIUMCVSS 5.3≥ 8.0.0, ≤ 9.1.32022-12-19
CVE-2022-37392 [MEDIUM] CWE-754 CVE-2022-37392: Improper Check for Unusual or Exceptional Conditions vulnerability in handling the requests to Apach
Improper Check for Unusual or Exceptional Conditions vulnerability in handling the requests to Apache Traffic Server. This issue affects Apache Traffic Server 8.0.0 to 9.1.2.
nvd
CVE-2024-56202P4MEDIUMCVSS 4.3≥ 9.0.0, ≤ 9.2.8≥ 10.0.0, ≤ 10.0.32025-03-06
CVE-2024-56202 [MEDIUM] CWE-440 CVE-2024-56202: Expected Behavior Violation vulnerability in Apache Traffic Server. This issue affects Apache Traff
Expected Behavior Violation vulnerability in Apache Traffic Server.
This issue affects Apache Traffic Server: from 9.0.0 through 9.2.8, from 10.0.0 through 10.0.3.
Users are recommended to upgrade to versions 9.2.9 or 10.0.4 or newer, which fixes the issue.
nvd
← Previous3 / 3