cbcvebase.

Apache Software Foundation Apache Traffic Server vulnerabilities

96 known vulnerabilities affecting apache_software_foundation/apache_traffic_server.

Total CVEs
96
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL15HIGH63MEDIUM18

Vulnerabilities

Page 5 of 5
CVE-2016-5396P3HIGHCVSS 7.5v6.0.0 to 6.2.02017-04-17
CVE-2016-5396 [HIGH] CWE-399 CVE-2016-5396: Apache Traffic Server 6.0.0 to 6.2.0 are affected by an HPACK Bomb Attack. Apache Traffic Server 6.0.0 to 6.2.0 are affected by an HPACK Bomb Attack.
nvd
CVE-2017-7671P3HIGHCVSS 7.5v5.2.0 to 5.3.2v6.0.0 to 6.2.0+1 more2018-02-27
CVE-2017-7671 [HIGH] CWE-20 CVE-2017-7671: There is a DOS attack vulnerability in Apache Traffic Server (ATS) 5.2.0 to 5.3.2, 6.0.0 to 6.2.0, a There is a DOS attack vulnerability in Apache Traffic Server (ATS) 5.2.0 to 5.3.2, 6.0.0 to 6.2.0, and 7.0.0 with the TLS handshake. This issue can cause the server to coredump.
nvd
CVE-2017-5659P3HIGHCVSS 7.5vAll versions prior to version 6.2.12017-04-17
CVE-2017-5659 [HIGH] CWE-20 CVE-2017-5659: Apache Traffic Server before 6.2.1 generates a coredump when there is a mismatch between content len Apache Traffic Server before 6.2.1 generates a coredump when there is a mismatch between content length and chunked encoding.
nvd
CVE-2026-33930P3MEDIUMCVSS 5.9≥ 8.0.0, ≤ 8.1.11≥ 9.0.0, ≤ 9.2.14+1 more2026-07-29
CVE-2026-33930 [MEDIUM] CWE-121 CVE-2026-33930: Apache Traffic Server copies the client Host header into a fixed-size stack buffer without a bound d Apache Traffic Server copies the client Host header into a fixed-size stack buffer without a bound during redirect handling, so an over-long Host header overflows the stack when redirect following is enabled. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.11, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are reco
nvd
CVE-2026-58158P3MEDIUMCVSS 5.9≥ 8.0.0, ≤ 8.1.11≥ 9.0.0, ≤ 9.2.14+1 more2026-07-29
CVE-2026-58158 [MEDIUM] CWE-121 CVE-2026-58158: Apache Traffic Server mishandles PROXY protocol input, truncating ports and overflowing the stack. Apache Traffic Server mishandles PROXY protocol input, truncating ports and overflowing the stack. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.11, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.
nvd
CVE-2018-8040P3MEDIUMCVSS 5.3v6.0.0 to 6.2.2v7.0.0 to 7.1.32018-08-29
CVE-2018-8040 [MEDIUM] CWE-668 CVE-2018-8040: Pages that are rendered using the ESI plugin can have access to the cookie header when the plugin is Pages that are rendered using the ESI plugin can have access to the cookie header when the plugin is configured not to allow access. This affects Apache Traffic Server (ATS) versions 6.0.0 to 6.2.2 and 7.0.0 to 7.1.3. To resolve this issue users running 6.x should upgrade to 6.2.3 or later versions and 7.x users should upgrade to 7.1.4 or later versio
nvd
CVE-2026-58152P3MEDIUMCVSS 5.9≥ 8.0.0, ≤ 8.1.11≥ 9.0.0, ≤ 9.2.14+1 more2026-07-29
CVE-2026-58152 [MEDIUM] CWE-190 CVE-2026-58152: Apache Traffic Server mishandles integers while decoding HPACK/XPACK headers, corrupting memory. Apache Traffic Server mishandles integers while decoding HPACK/XPACK headers, corrupting memory. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.11, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.
nvd
CVE-2018-8005P4MEDIUMCVSS 5.3v6.0.0 to 6.2.2v7.0.0 to 7.1.32018-08-29
CVE-2018-8005 [MEDIUM] CWE-400 CVE-2018-8005: When there are multiple ranges in a range request, Apache Traffic Server (ATS) will read the entire When there are multiple ranges in a range request, Apache Traffic Server (ATS) will read the entire object from cache. This can cause performance problems with large objects in cache. This affects versions 6.0.0 to 6.2.2 and 7.0.0 to 7.1.3. To resolve this issue users running 6.x users should upgrade to 6.2.3 or later versions and 7.x users should upgr
nvd
CVE-2026-24033P4MEDIUMCVSS 5.3≥ 10.0.0, ≤ 10.1.3≥ 9.0.0, ≤ 9.2.142026-07-29
CVE-2026-24033 [MEDIUM] CWE-444 CVE-2026-24033: Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') vulnerability in Ap Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') vulnerability in Apache Traffic Server. This issue affects Apache Traffic Server: from 10.0.0 through 10.1.3, from 9.0.0 through 9.2.14. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fixes the issue.
nvd
CVE-2026-22068P4MEDIUMCVSS 5.3≥ 10.0.x, ≤ 10.1.3≥ 9.0.x, ≤ 9.2.142026-07-29
CVE-2026-22068 [MEDIUM] CWE-777 CVE-2026-22068: Regular Expression without Anchors vulnerability in Apache Traffic Server. This issue affects Apach Regular Expression without Anchors vulnerability in Apache Traffic Server. This issue affects Apache Traffic Server: from 10.0.X through 10.1.3, from 9.0.X through 9.2.14. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fixes the issue.
nvd
CVE-2026-58156P4MEDIUMCVSS 4.9≥ 8.0.0, ≤ 8.1.11≥ 9.0.0, ≤ 9.2.14+1 more2026-07-29
CVE-2026-58156 [MEDIUM] CWE-863 CVE-2026-58156: Apache Traffic Server mis-parses ports in URLs and userinfo, allowing port-based access-control bypa Apache Traffic Server mis-parses ports in URLs and userinfo, allowing port-based access-control bypass. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.11, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.
nvd
CVE-2026-65100P4MEDIUMCVSS 4.8≥ 8.0.0, ≤ 8.1.11≥ 9.0.0, ≤ 9.2.14+1 more2026-07-29
CVE-2026-65100 [MEDIUM] CWE-696 CVE-2026-65100: Apache Traffic Server updates the HTTP/2 HPACK dynamic table before confirming the header block enco Apache Traffic Server updates the HTTP/2 HPACK dynamic table before confirming the header block encoded successfully, so an encode failure leaves the encoder out of sync with the peer decoder and corrupts subsequent header blocks on the connection. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.11, from 9.0.0 through 9.2.14, from
nvd
CVE-2026-65325P4MEDIUMCVSS 4.8≥ 9.0.0, ≤ 9.2.14≥ 10.0.0, ≤ 10.1.32026-07-29
CVE-2026-65325 [MEDIUM] CWE-295 CVE-2026-65325: Apache Traffic Server reuses multiplexed HTTP/2 origin connections without verifying the server cert Apache Traffic Server reuses multiplexed HTTP/2 origin connections without verifying the server certificate covers the new request hostname. This issue affects Apache Traffic Server: from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.
nvd
CVE-2022-40743P4MEDIUMCVSS 6.1≥ 9.0.0, ≤ 9.1.32022-12-19
CVE-2022-40743 [MEDIUM] CWE-79 CVE-2022-40743: Improper Input Validation vulnerability for the xdebug plugin in Apache Software Foundation Apache T Improper Input Validation vulnerability for the xdebug plugin in Apache Software Foundation Apache Traffic Server can lead to cross site scripting and cache poisoning attacks.This issue affects Apache Traffic Server: 9.0.0 to 9.1.3. Users should upgrade to 9.1.4 or later versions.
nvd
CVE-2022-37392P4MEDIUMCVSS 5.3≥ 8.0.0, ≤ 9.1.32022-12-19
CVE-2022-37392 [MEDIUM] CWE-754 CVE-2022-37392: Improper Check for Unusual or Exceptional Conditions vulnerability in handling the requests to Apach Improper Check for Unusual or Exceptional Conditions vulnerability in handling the requests to Apache Traffic Server. This issue affects Apache Traffic Server 8.0.0 to 9.1.2.
nvd
CVE-2024-56202P4MEDIUMCVSS 4.3≥ 9.0.0, ≤ 9.2.8≥ 10.0.0, ≤ 10.0.32025-03-06
CVE-2024-56202 [MEDIUM] CWE-440 CVE-2024-56202: Expected Behavior Violation vulnerability in Apache Traffic Server. This issue affects Apache Traff Expected Behavior Violation vulnerability in Apache Traffic Server. This issue affects Apache Traffic Server: from 9.0.0 through 9.2.8, from 10.0.0 through 10.0.3. Users are recommended to upgrade to versions 9.2.9 or 10.0.4 or newer, which fixes the issue.
nvd
Apache Software Foundation Apache Traffic Server vulnerabilities | cvebase