cbcvebase.

Apache Software Foundation Apache Traffic Server vulnerabilities

96 known vulnerabilities affecting apache_software_foundation/apache_traffic_server.

Total CVEs
96
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL15HIGH63MEDIUM18

Vulnerabilities

Page 3 of 5
CVE-2026-58175P3HIGHCVSS 7.5≥ 8.0.0, ≤ 8.1.11≥ 9.0.0, ≤ 9.2.14+1 more2026-07-29
CVE-2026-58175 [HIGH] CWE-401 CVE-2026-58175: Apache Traffic Server leaks memory when handling HostDB SRV records. This issue affects Apache Tr Apache Traffic Server leaks memory when handling HostDB SRV records. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.11, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.
nvd
CVE-2024-53868P3HIGHCVSS 7.5≥ 9.2.0, ≤ 9.2.9≥ 10.0.0, ≤ 10.0.42025-04-03
CVE-2024-53868 [HIGH] CWE-444 CVE-2024-53868: Apache Traffic Server allows request smuggling if chunked messages are malformed. This issue a Apache Traffic Server allows request smuggling if chunked messages are malformed. This issue affects Apache Traffic Server: from 9.2.0 through 9.2.9, from 10.0.0 through 10.0.4. Users are recommended to upgrade to version 9.2.10 or 10.0.5, which fixes the issue.
nvd
CVE-2025-31698P3HIGHCVSS 7.5≥ 10.0.0, ≤ 10.0.6≥ 9.0.0, ≤ 9.2.102025-06-19
CVE-2025-31698 [HIGH] CWE-284 CVE-2025-31698: ACL configured in ip_allow.config or remap.config does not use IP addresses that are provided by PRO ACL configured in ip_allow.config or remap.config does not use IP addresses that are provided by PROXY protocol. Users can use a new setting (proxy.config.acl.subjects) to choose which IP addresses to use for the ACL if Apache Traffic Server is configured to accept PROXY protocol. This issue affects undefined: from 10.0.0 through 10.0.6, from 9.0.0 t
nvd
CVE-2021-38161P3HIGHCVSS 8.1v8.0.0 to 8.0.82021-11-03
CVE-2021-38161 [HIGH] CWE-287 CVE-2021-38161: Improper Authentication vulnerability in TLS origin verification of Apache Traffic Server allows for Improper Authentication vulnerability in TLS origin verification of Apache Traffic Server allows for man in the middle attacks. This issue affects Apache Traffic Server 8.0.0 to 8.0.8.
nvd
CVE-2021-27577P3HIGHCVSS 7.5vApache Traffic Server 7.0.0 to 7.1.12, 8.0.0 to 8.1.1, 9.0.0 to 9.0.12021-06-29
CVE-2021-27577 [HIGH] CWE-444 CVE-2021-27577: Incorrect handling of url fragment vulnerability of Apache Traffic Server allows an attacker to pois Incorrect handling of url fragment vulnerability of Apache Traffic Server allows an attacker to poison the cache. This issue affects Apache Traffic Server 7.0.0 to 7.1.12, 8.0.0 to 8.1.1, 9.0.0 to 9.0.1.
nvd
CVE-2024-35296P3HIGHCVSS 8.2≥ 8.0.0, ≤ 8.1.10≥ 9.0.0, ≤ 9.2.42024-07-26
CVE-2024-35296 [HIGH] CWE-20 CVE-2024-35296: Invalid Accept-Encoding header can cause Apache Traffic Server to fail cache lookup and force forwar Invalid Accept-Encoding header can cause Apache Traffic Server to fail cache lookup and force forwarding requests. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.10, from 9.0.0 through 9.2.4. Users are recommended to upgrade to version 8.1.11 or 9.2.5, which fixes the issue.
nvd
CVE-2022-31779P3HIGHCVSS 7.5v8.0.0 to 9.1.22022-08-10
CVE-2022-31779 [HIGH] CWE-20 CVE-2022-31779: Improper Input Validation vulnerability in HTTP/2 header parsing of Apache Traffic Server allows an Improper Input Validation vulnerability in HTTP/2 header parsing of Apache Traffic Server allows an attacker to smuggle requests. This issue affects Apache Traffic Server 8.0.0 to 9.1.2.
nvd
CVE-2021-37150P3HIGHCVSS 7.5v8.0.0 to 9.1.22022-08-10
CVE-2021-37150 [HIGH] CWE-20 CVE-2021-37150: Improper Input Validation vulnerability in header parsing of Apache Traffic Server allows an attacke Improper Input Validation vulnerability in header parsing of Apache Traffic Server allows an attacker to request secure resources. This issue affects Apache Traffic Server 8.0.0 to 9.1.2.
nvd
CVE-2026-58187P3HIGHCVSS 7.5≥ 8.0.0, ≤ 8.1.11≥ 9.0.0, ≤ 9.2.14+1 more2026-07-29
CVE-2026-58187 [HIGH] CWE-787 CVE-2026-58187: The Apache Traffic Server multiplexer plugin overruns its chunk-decode buffer on upstream input, ena The Apache Traffic Server multiplexer plugin overruns its chunk-decode buffer on upstream input, enabling denial of service. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.11, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.
nvd
CVE-2017-5660P3HIGHCVSS 8.6v6.2.0 and priorv7.0.0 and prior2018-02-27
CVE-2017-5660 [HIGH] CWE-20 CVE-2017-5660: There is a vulnerability in Apache Traffic Server (ATS) 6.2.0 and prior and 7.0.0 and prior with the There is a vulnerability in Apache Traffic Server (ATS) 6.2.0 and prior and 7.0.0 and prior with the Host header and line folding. This can have issues when interacting with upstream proxies and the wrong host being used.
nvd
CVE-2022-28129P3HIGHCVSS 7.5v8.0.0 to 9.1.22022-08-10
CVE-2022-28129 [HIGH] CWE-20 CVE-2022-28129: Improper Input Validation vulnerability in HTTP/1.1 header parsing of Apache Traffic Server allows a Improper Input Validation vulnerability in HTTP/1.1 header parsing of Apache Traffic Server allows an attacker to send invalid headers. This issue affects Apache Traffic Server 8.0.0 to 9.1.2.
nvd
CVE-2022-31780P3HIGHCVSS 7.5v8.0.0 to 9.1.22022-08-10
CVE-2022-31780 [HIGH] CWE-20 CVE-2022-31780: Improper Input Validation vulnerability in HTTP/2 frame handling of Apache Traffic Server allows an Improper Input Validation vulnerability in HTTP/2 frame handling of Apache Traffic Server allows an attacker to smuggle requests. This issue affects Apache Traffic Server 8.0.0 to 9.1.2.
nvd
CVE-2023-30631P3HIGHCVSS 7.5≥ 8.0.0, ≤ 9.2.02023-06-14
CVE-2023-30631 [HIGH] CWE-20 CVE-2023-30631: Improper Input Validation vulnerability in Apache Software Foundation Apache Traffic Server. The co Improper Input Validation vulnerability in Apache Software Foundation Apache Traffic Server. The configuration option proxy.config.http.push_method_enabled didn't function. However, by default the PUSH method is blocked in the ip_allow configuration file.This issue affects Apache Traffic Server: from 8.0.0 through 9.2.0. 8.x users should upgrade to 8.1
nvd
CVE-2021-44040P3HIGHCVSS 7.5v8.0.0 to 8.1.3 and 9.0.0 to 9.1.12022-03-23
CVE-2021-44040 [HIGH] CWE-20 CVE-2021-44040: Improper Input Validation vulnerability in request line parsing of Apache Traffic Server allows an a Improper Input Validation vulnerability in request line parsing of Apache Traffic Server allows an attacker to send invalid requests. This issue affects Apache Traffic Server 8.0.0 to 8.1.3 and 9.0.0 to 9.1.1.
nvd
CVE-2018-8022P3HIGHCVSS 7.5v6.2.22018-08-29
CVE-2018-8022 [HIGH] CWE-20 CVE-2018-8022: A carefully crafted invalid TLS handshake can cause Apache Traffic Server (ATS) to segfault. This af A carefully crafted invalid TLS handshake can cause Apache Traffic Server (ATS) to segfault. This affects version 6.2.2. To resolve this issue users running 6.2.2 should upgrade to 6.2.3 or later versions.
nvd
CVE-2023-38522P3HIGHCVSS 7.5≥ 8.0.0, ≤ 8.1.10≥ 9.0.0, ≤ 9.2.42024-07-26
CVE-2023-38522 [HIGH] CWE-444 CVE-2023-38522: Apache Traffic Server accepts characters that are not allowed for HTTP field names and forwards malf Apache Traffic Server accepts characters that are not allowed for HTTP field names and forwards malformed requests to origin servers. This can be utilized for request smuggling and may also lead cache poisoning if the origin servers are vulnerable. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.10, from 9.0.0 through 9.2.4. Users a
nvd
CVE-2024-35161P3HIGHCVSS 7.5≥ 8.0.0, ≤ 8.1.10≥ 9.0.0, ≤ 9.2.42024-07-26
CVE-2024-35161 [HIGH] CWE-444 CVE-2024-35161: Apache Traffic Server forwards malformed HTTP chunked trailer section to origin servers. This can be Apache Traffic Server forwards malformed HTTP chunked trailer section to origin servers. This can be utilized for request smuggling and may also lead cache poisoning if the origin servers are vulnerable. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.10, from 9.0.0 through 9.2.4. Users can set a new setting (proxy.config.http.drop_
nvd
CVE-2024-38479P3HIGHCVSS 7.5≥ 8.0.0, ≤ 8.1.11≥ 9.0.0, ≤ 9.2.52024-11-14
CVE-2024-38479 [HIGH] CWE-20 CVE-2024-38479: Improper Input Validation vulnerability in Apache Traffic Server. This issue affects Apache Traffic Improper Input Validation vulnerability in Apache Traffic Server. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.11, from 9.0.0 through 9.2.5. Users are recommended to upgrade to version 9.2.6, which fixes the issue, or 10.0.2, which does not have the issue.
nvd
CVE-2021-37149P3HIGHCVSS 7.5v8.0.0 to 8.1.2 and 9.0.0 to 9.1.02021-11-03
CVE-2021-37149 [HIGH] CWE-20 CVE-2021-37149: Improper Input Validation vulnerability in header parsing of Apache Traffic Server allows an attacke Improper Input Validation vulnerability in header parsing of Apache Traffic Server allows an attacker to smuggle requests. This issue affects Apache Traffic Server 8.0.0 to 8.1.2 and 9.0.0 to 9.1.0.
nvd
CVE-2021-37148P3HIGHCVSS 7.5v8.0.0 to 8.1.2 and 9.0.0 to 9.0.12021-11-03
CVE-2021-37148 [HIGH] CWE-20 CVE-2021-37148: Improper input validation vulnerability in header parsing of Apache Traffic Server allows an attacke Improper input validation vulnerability in header parsing of Apache Traffic Server allows an attacker to smuggle requests. This issue affects Apache Traffic Server 8.0.0 to 8.1.2 and 9.0.0 to 9.0.1.
nvd
Apache Software Foundation Apache Traffic Server vulnerabilities | cvebase