Apache Software Foundation Apache Traffic Server vulnerabilities
96 known vulnerabilities affecting apache_software_foundation/apache_traffic_server.
Total CVEs
96
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL15HIGH63MEDIUM18
Vulnerabilities
Page 4 of 5
CVE-2021-37147P3HIGHCVSS 7.5v8.0.0 to 8.1.2 and 9.0.0 to 9.1.02021-11-03
CVE-2021-37147 [HIGH] CWE-20 CVE-2021-37147: Improper input validation vulnerability in header parsing of Apache Traffic Server allows an attacke
Improper input validation vulnerability in header parsing of Apache Traffic Server allows an attacker to smuggle requests. This issue affects Apache Traffic Server 8.0.0 to 8.1.2 and 9.0.0 to 9.1.0.
nvd
CVE-2021-32565P3HIGHCVSS 7.5vApache Traffic Server 7.0.0 to 7.1.12, 8.0.0 to 8.1.1, 9.0.0 to 9.0.12021-06-29
CVE-2021-32565 [HIGH] CWE-444 CVE-2021-32565: Invalid values in the Content-Length header sent to Apache Traffic Server allows an attacker to smug
Invalid values in the Content-Length header sent to Apache Traffic Server allows an attacker to smuggle requests. This issue affects Apache Traffic Server 7.0.0 to 7.1.12, 8.0.0 to 8.1.1, 9.0.0 to 9.0.1.
nvd
CVE-2022-31778P3HIGHCVSS 7.5v8.0.0 to 9.0.22022-08-10
CVE-2022-31778 [HIGH] CWE-20 CVE-2022-31778: Improper Input Validation vulnerability in handling the Transfer-Encoding header of Apache Traffic S
Improper Input Validation vulnerability in handling the Transfer-Encoding header of Apache Traffic Server allows an attacker to poison the cache. This issue affects Apache Traffic Server 8.0.0 to 9.0.2.
nvd
CVE-2025-49763P3HIGHCVSS 7.5≥ 10.0.0, ≤ 10.0.5≥ 9.0.0, ≤ 9.2.102025-06-19
CVE-2025-49763 [HIGH] CWE-400 CVE-2025-49763: ESI plugin does not have the limit for maximum inclusion depth, and that allows excessive memory con
ESI plugin does not have the limit for maximum inclusion depth, and that allows excessive memory consumption if malicious instructions are inserted.
Users can use a new setting for the plugin (--max-inclusion-depth) to limit it.
This issue affects Apache Traffic Server: from 10.0.0 through 10.0.5, from 9.0.0 through 9.2.10.
Users are recommended to
nvd
CVE-2021-32566P3HIGHCVSS 7.5vApache Traffic Server 7.0.0 to 7.1.12, 8.0.0 to 8.1.1, 9.0.0 to 9.0.12021-06-30
CVE-2021-32566 [HIGH] CWE-20 CVE-2021-32566: Improper Input Validation vulnerability in HTTP/2 of Apache Traffic Server allows an attacker to DOS
Improper Input Validation vulnerability in HTTP/2 of Apache Traffic Server allows an attacker to DOS the server. This issue affects Apache Traffic Server 7.0.0 to 7.1.12, 8.0.0 to 8.1.1, 9.0.0 to 9.0.1.
nvd
CVE-2021-32567P3HIGHCVSS 7.5vApache Traffic Server 7.0.0 to 7.1.12, 8.0.0 to 8.1.1, 9.0.0 to 9.0.12021-06-30
CVE-2021-32567 [HIGH] CWE-20 CVE-2021-32567: Improper Input Validation vulnerability in HTTP/2 of Apache Traffic Server allows an attacker to DOS
Improper Input Validation vulnerability in HTTP/2 of Apache Traffic Server allows an attacker to DOS the server. This issue affects Apache Traffic Server 7.0.0 to 7.1.12, 8.0.0 to 8.1.1, 9.0.0 to 9.0.1.
nvd
CVE-2023-41752P3HIGHCVSS 7.5≥ 8.0.0, ≤ 8.1.8≥ 9.0.0, ≤ 9.2.22023-10-17
CVE-2023-41752 [HIGH] CWE-200 CVE-2023-41752: Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Traffic Server.Th
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Traffic Server.This issue affects Apache Traffic Server: from 8.0.0 through 8.1.8, from 9.0.0 through 9.2.2.
Users are recommended to upgrade to version 8.1.9 or 9.2.3, which fixes the issue.
nvd
CVE-2021-41585P3HIGHCVSS 7.5v7.0.0 to 9.1.02021-11-03
CVE-2021-41585 [HIGH] CWE-20 CVE-2021-41585: Improper Input Validation vulnerability in accepting socket connections in Apache Traffic Server all
Improper Input Validation vulnerability in accepting socket connections in Apache Traffic Server allows an attacker to make the server stop accepting new connections. This issue affects Apache Traffic Server 5.0.0 to 9.1.0.
nvd
CVE-2022-47185P3HIGHCVSS 7.5≤ 9.2.12023-08-09
CVE-2022-47185 [HIGH] CWE-20 CVE-2022-47185: Improper input validation vulnerability on the range header in Apache Software Foundation Apache Tra
Improper input validation vulnerability on the range header in Apache Software Foundation Apache Traffic Server.This issue affects Apache Traffic Server: through 9.2.1.
nvd
CVE-2023-33933P3HIGHCVSS 7.5≥ 8.0.0, ≤ 9.2.02023-06-14
CVE-2023-33933 [HIGH] CWE-200 CVE-2023-33933: Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Software Foundati
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Software Foundation Apache Traffic Server.This issue affects Apache Traffic Server: from 8.0.0 through 9.2.0.
8.x users should upgrade to 8.1.7 or later versions
9.x users should upgrade to 9.2.1 or later versions
nvd
CVE-2022-47184P3HIGHCVSS 7.5≥ 8.0.0, ≤ 9.2.02023-06-14
CVE-2022-47184 [HIGH] CWE-200 CVE-2022-47184: Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Software Foundati
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Software Foundation Apache Traffic Server.This issue affects Apache Traffic Server: 8.0.0 to 9.2.0.
nvd
CVE-2018-8004P3MEDIUMCVSS 6.5v6.0.0 to 6.2.2v7.0.0 to 7.1.32018-08-29
CVE-2018-8004 [MEDIUM] CWE-444 CVE-2018-8004: There are multiple HTTP smuggling and cache poisoning issues when clients making malicious requests
There are multiple HTTP smuggling and cache poisoning issues when clients making malicious requests interact with Apache Traffic Server (ATS). This affects versions 6.0.0 to 6.2.2 and 7.0.0 to 7.1.3. To resolve this issue users running 6.x should upgrade to 6.2.3 or later versions and 7.x users should upgrade to 7.1.4 or later versions.
nvd
CVE-2022-32749P3HIGHCVSS 7.5≥ 8.0.0, ≤ 9.1.32022-12-19
CVE-2022-32749 [HIGH] CWE-754 CVE-2022-32749: Improper Check for Unusual or Exceptional Conditions vulnerability handling requests in Apache Traf
Improper Check for Unusual or Exceptional Conditions vulnerability handling requests in Apache Traffic Server allows an attacker to crash the server under certain conditions.
This issue affects Apache Traffic Server: from 8.0.0 through 9.1.3.
nvd
CVE-2020-9494P3HIGHCVSS 7.5v6.0.0 to 6.2.3v7.0.0 to 7.1.10+1 more2020-06-24
CVE-2020-9494 [HIGH] CWE-770 CVE-2020-9494: Apache Traffic Server 6.0.0 to 6.2.3, 7.0.0 to 7.1.10, and 8.0.0 to 8.0.7 is vulnerable to certain t
Apache Traffic Server 6.0.0 to 6.2.3, 7.0.0 to 7.1.10, and 8.0.0 to 8.0.7 is vulnerable to certain types of HTTP/2 HEADERS frames that can cause the server to allocate a large amount of memory and spin the thread.
nvd
CVE-2018-11783P3HIGHCVSS 7.5vApache Traffic Server 6.0.0 to 6.0.3, 7.0.0 to 7.1.5, 8.0.0 to 8.0.12019-03-07
CVE-2018-11783 [HIGH] CWE-200 CVE-2018-11783: sslheaders plugin extracts information from the client certificate and sets headers in the request b
sslheaders plugin extracts information from the client certificate and sets headers in the request based on the configuration of the plugin. The plugin doesn't strip the headers from the request in some scenarios. This problem was discovered in versions 6.0.0 to 6.0.3, 7.0.0 to 7.1.5, and 8.0.0 to 8.0.1.
nvd
CVE-2024-50305P3HIGHCVSS 7.5≥ 9.2.0, ≤ 9.2.52024-11-14
CVE-2024-50305 [HIGH] CWE-20 CVE-2024-50305: Valid Host header field can cause Apache Traffic Server to crash on some platforms. This issue affe
Valid Host header field can cause Apache Traffic Server to crash on some platforms.
This issue affects Apache Traffic Server: from 9.2.0 through 9.2.5.
Users are recommended to upgrade to version 9.2.6, which fixes the issue, or 10.0.2, which does not have the issue.
nvd
CVE-2026-58160P3MEDIUMCVSS 6.5≥ 8.0.0, ≤ 8.1.11≥ 9.0.0, ≤ 9.2.14+1 more2026-07-29
CVE-2026-58160 [MEDIUM] CWE-125 CVE-2026-58160: Apache Traffic Server reads out of bounds while parsing DNS answers. This issue affects Apache Tr
Apache Traffic Server reads out of bounds while parsing DNS answers.
This issue affects Apache Traffic Server: from 8.0.0 through 8.1.11, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3.
Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.
nvd
CVE-2024-56195P3MEDIUMCVSS 6.3≥ 9.2.0, ≤ 9.2.8≥ 10.0.0, ≤ 10.0.32025-03-06
CVE-2024-56195 [MEDIUM] CWE-284 CVE-2024-56195: Improper Access Control vulnerability in Apache Traffic Server. This issue affects Apache Traffic S
Improper Access Control vulnerability in Apache Traffic Server.
This issue affects Apache Traffic Server: from 9.2.0 through 9.2.8, from 10.0.0 through 10.0.3.
Users are recommended to upgrade to version 9.2.9 or 10.0.4, which fixes the issue.
nvd
CVE-2024-38311P3MEDIUMCVSS 6.3≥ 8.0.0, ≤ 8.1.11≥ 9.0.0, ≤ 9.2.8+1 more2025-03-06
CVE-2024-38311 [MEDIUM] CWE-20 CVE-2024-38311: Improper Input Validation vulnerability in Apache Traffic Server. This issue affects Apache Traffic
Improper Input Validation vulnerability in Apache Traffic Server.
This issue affects Apache Traffic Server: from 8.0.0 through 8.1.11, from 9.0.0 through 9.2.8, from 10.0.0 through 10.0.3.
Users are recommended to upgrade to version 9.2.9 or 10.0.4, which fixes the issue.
nvd
CVE-2024-56196P3MEDIUMCVSS 6.3≥ 10.0.0, ≤ 10.0.32025-03-06
CVE-2024-56196 [MEDIUM] CWE-284 CVE-2024-56196: Improper Access Control vulnerability in Apache Traffic Server. This issue affects Apache Traffic S
Improper Access Control vulnerability in Apache Traffic Server.
This issue affects Apache Traffic Server: from 10.0.0 through 10.0.3.
Users are recommended to upgrade to version 10.0.4, which fixes the issue.
nvd