Debian Trafficserver vulnerabilities
73 known vulnerabilities affecting debian/trafficserver.
Total CVEs
73
CISA KEV
1
actively exploited
Public exploits
1
Exploited in wild
1
Severity breakdown
CRITICAL11HIGH51MEDIUM10LOW1
Vulnerabilities
Page 1 of 4
CVE-2023-44487P1HIGHCVSS 7.5KEVPoCfixed in dnsdist 1.8.2-2 (forky)2023
CVE-2023-44487 [HIGH] CVE-2023-44487: dnsdist - The HTTP/2 protocol allows a denial of service (server resource consumption) bec...
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.
Scope: local
bookworm: open
bullseye: open
forky: resolved (fixed in 1.8.2-2)
sid: resolved (fixed in 1.8.2-2)
trixie: resolved (fixed in 1.8.2-2)
debian
CVE-2024-31309P2HIGHCVSS 7.5fixed in trafficserver 9.2.4+ds-0+deb12u1 (bookworm)2024
CVE-2024-31309 [HIGH] CVE-2024-31309: trafficserver - HTTP/2 CONTINUATION DoS attack can cause Apache Traffic Server to consume more r...
HTTP/2 CONTINUATION DoS attack can cause Apache Traffic Server to consume more resources on the server. Version from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.3 are affected. Users can set a new setting (proxy.config.http2.max_continuation_frames_per_minute) to limit the number of CONTINUATION frames per minute. ATS does have a fixed amount of memory a reque
debian
CVE-2019-9515P3HIGHCVSS 7.5fixed in h2o 2.2.5+dfsg2-3 (bookworm)2019
CVE-2019-9515 [HIGH] CVE-2019-9515: h2o - Some HTTP/2 implementations are vulnerable to a settings flood, potentially lead...
Some HTTP/2 implementations are vulnerable to a settings flood, potentially leading to a denial of service. The attacker sends a stream of SETTINGS frames to the peer. Since the RFC requires that the peer reply with one acknowledgement per SETTINGS frame, an empty SETTINGS frame is almost equivalent in behavior to a ping. Depending on how efficiently this data is queued,
debian
CVE-2019-9512P3HIGHCVSS 7.5fixed in h2o 2.2.5+dfsg2-3 (bookworm)2019
CVE-2019-9512 [HIGH] CVE-2019-9512: h2o - Some HTTP/2 implementations are vulnerable to ping floods, potentially leading t...
Some HTTP/2 implementations are vulnerable to ping floods, potentially leading to a denial of service. The attacker sends continual pings to an HTTP/2 peer, causing the peer to build an internal queue of responses. Depending on how efficiently this data is queued, this can consume excess CPU, memory, or both.
Scope: local
bookworm: resolved (fixed in 2.2.5+dfsg2-3)
bullse
debian
CVE-2019-9514P3HIGHCVSS 7.5fixed in h2o 2.2.5+dfsg2-3 (bookworm)2019
CVE-2019-9514 [HIGH] CVE-2019-9514: h2o - Some HTTP/2 implementations are vulnerable to a reset flood, potentially leading...
Some HTTP/2 implementations are vulnerable to a reset flood, potentially leading to a denial of service. The attacker opens a number of streams and sends an invalid request over each stream that should solicit a stream of RST_STREAM frames from the peer. Depending on how the peer queues the RST_STREAM frames, this can consume excess memory, CPU, or both.
Scope: local
book
debian
CVE-2023-39456P3HIGHCVSS 7.5fixed in trafficserver 9.2.3+ds-1+deb12u1 (bookworm)2023
CVE-2023-39456 [HIGH] CVE-2023-39456: trafficserver - Improper Input Validation vulnerability in Apache Traffic Server with malformed ...
Improper Input Validation vulnerability in Apache Traffic Server with malformed HTTP/2 frames.This issue affects Apache Traffic Server: from 9.0.0 through 9.2.2. Users are recommended to upgrade to version 9.2.3, which fixes the issue.
Scope: local
bookworm: resolved (fixed in 9.2.3+ds-1+deb12u1)
bullseye: resolved
sid: resolved (fixed in 9.2.3+ds-1)
debian
CVE-2014-3624P3CRITICALCVSS 9.8fixed in trafficserver 5.0.0-1 (bookworm)2014
CVE-2014-3624 [CRITICAL] CVE-2014-3624: trafficserver - Apache Traffic Server 5.1.x before 5.1.1 allows remote attackers to bypass acces...
Apache Traffic Server 5.1.x before 5.1.1 allows remote attackers to bypass access restrictions by leveraging failure to properly tunnel remap requests using CONNECT.
Scope: local
bookworm: resolved (fixed in 5.0.0-1)
bullseye: resolved (fixed in 5.0.0-1)
sid: resolved (fixed in 5.0.0-1)
debian
CVE-2021-35474P3CRITICALCVSS 9.8fixed in trafficserver 8.1.1+ds-1.1 (bookworm)2021
CVE-2021-35474 [CRITICAL] CVE-2021-35474: trafficserver - Stack-based Buffer Overflow vulnerability in cachekey plugin of Apache Traffic S...
Stack-based Buffer Overflow vulnerability in cachekey plugin of Apache Traffic Server. This issue affects Apache Traffic Server 7.0.0 to 7.1.12, 8.0.0 to 8.1.1, 9.0.0 to 9.0.1.
Scope: local
bookworm: resolved (fixed in 8.1.1+ds-1.1)
bullseye: resolved (fixed in 8.1.1+ds-1.1)
sid: resolved (fixed in 8.1.1+ds-1.1)
debian
CVE-2021-43082P3CRITICALCVSS 9.8fixed in trafficserver 9.1.1+ds-1 (bookworm)2021
CVE-2021-43082 [CRITICAL] CVE-2021-43082: trafficserver - Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerabi...
Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in the stats-over-http plugin of Apache Traffic Server allows an attacker to overwrite memory. This issue affects Apache Traffic Server 9.1.0.
Scope: local
bookworm: resolved (fixed in 9.1.1+ds-1)
bullseye: resolved
sid: resolved (fixed in 9.1.1+ds-1)
debian
CVE-2024-50306P3CRITICALCVSS 9.1fixed in trafficserver 9.2.5+ds-0+deb12u2 (bookworm)2024
CVE-2024-50306 [CRITICAL] CVE-2024-50306: trafficserver - Unchecked return value can allow Apache Traffic Server to retain privileges on s...
Unchecked return value can allow Apache Traffic Server to retain privileges on startup. This issue affects Apache Traffic Server: from 9.2.0 through 9.2.5, from 10.0.0 through 10.0.1. Users are recommended to upgrade to version 9.2.6 or 10.0.2, which fixes the issue.
Scope: local
bookworm: resolved (fixed in 9.2.5+ds-0+deb12u2)
bullseye: resolved (fixed in
debian
CVE-2019-9518P3HIGHCVSS 7.5fixed in trafficserver 8.0.5+ds-1 (bookworm)2019
CVE-2019-9518 [HIGH] CVE-2019-9518: trafficserver - Some HTTP/2 implementations are vulnerable to a flood of empty frames, potential...
Some HTTP/2 implementations are vulnerable to a flood of empty frames, potentially leading to a denial of service. The attacker sends a stream of frames with an empty payload and without the end-of-stream flag. These frames can be DATA, HEADERS, CONTINUATION and/or PUSH_PROMISE. The peer spends time processing each frame disproportionate to attack bandwidth. Thi
debian
CVE-2019-17559P3CRITICALCVSS 9.8fixed in trafficserver 8.0.6+ds-1 (bookworm)2019
CVE-2019-17559 [CRITICAL] CVE-2019-17559: trafficserver - There is a vulnerability in Apache Traffic Server 6.0.0 to 6.2.3, 7.0.0 to 7.1.8...
There is a vulnerability in Apache Traffic Server 6.0.0 to 6.2.3, 7.0.0 to 7.1.8, and 8.0.0 to 8.0.5 with a smuggling attack and scheme parsing. Upgrade to versions 7.1.9 and 8.0.6 or later versions.
Scope: local
bookworm: resolved (fixed in 8.0.6+ds-1)
bullseye: resolved (fixed in 8.0.6+ds-1)
sid: resolved (fixed in 8.0.6+ds-1)
debian
CVE-2019-17565P3CRITICALCVSS 9.8fixed in trafficserver 8.0.6+ds-1 (bookworm)2019
CVE-2019-17565 [CRITICAL] CVE-2019-17565: trafficserver - There is a vulnerability in Apache Traffic Server 6.0.0 to 6.2.3, 7.0.0 to 7.1.8...
There is a vulnerability in Apache Traffic Server 6.0.0 to 6.2.3, 7.0.0 to 7.1.8, and 8.0.0 to 8.0.5 with a smuggling attack and chunked encoding. Upgrade to versions 7.1.9 and 8.0.6 or later versions.
Scope: local
bookworm: resolved (fixed in 8.0.6+ds-1)
bullseye: resolved (fixed in 8.0.6+ds-1)
sid: resolved (fixed in 8.0.6+ds-1)
debian
CVE-2015-3249P3CRITICALCVSS 9.8fixed in trafficserver 5.3.1-1 (bookworm)2015
CVE-2015-3249 [CRITICAL] CVE-2015-3249: trafficserver - The HTTP/2 experimental feature in Apache Traffic Server 5.3.x before 5.3.1 allo...
The HTTP/2 experimental feature in Apache Traffic Server 5.3.x before 5.3.1 allows remote attackers to cause a denial of service (out-of-bounds access and daemon crash) or possibly execute arbitrary code via vectors related to the (1) frame_handlers array or (2) set_dynamic_table_size function.
Scope: local
bookworm: resolved (fixed in 5.3.1-1)
bullseye: res
debian
CVE-2023-33934P3CRITICALCVSS 9.1fixed in trafficserver 9.2.3+ds-1+deb12u1 (bookworm)2023
CVE-2023-33934 [CRITICAL] CVE-2023-33934: trafficserver - Improper Input Validation vulnerability in Apache Software Foundation Apache Tra...
Improper Input Validation vulnerability in Apache Software Foundation Apache Traffic Server.This issue affects Apache Traffic Server: through 9.2.1.
Scope: local
bookworm: resolved (fixed in 9.2.3+ds-1+deb12u1)
bullseye: resolved (fixed in 8.1.9+ds-1~deb11u1)
sid: resolved (fixed in 9.2.2+ds-1)
debian
CVE-2020-1944P3CRITICALCVSS 9.8fixed in trafficserver 8.0.6+ds-1 (bookworm)2020
CVE-2020-1944 [CRITICAL] CVE-2020-1944: trafficserver - There is a vulnerability in Apache Traffic Server 6.0.0 to 6.2.3, 7.0.0 to 7.1.8...
There is a vulnerability in Apache Traffic Server 6.0.0 to 6.2.3, 7.0.0 to 7.1.8, and 8.0.0 to 8.0.5 with a smuggling attack and Transfer-Encoding and Content length headers. Upgrade to versions 7.1.9 and 8.0.6 or later versions.
Scope: local
bookworm: resolved (fixed in 8.0.6+ds-1)
bullseye: resolved (fixed in 8.0.6+ds-1)
sid: resolved (fixed in 8.0.6+ds-1)
debian
CVE-2018-1318P3HIGHCVSS 7.5fixed in trafficserver 7.1.4+ds-1 (bookworm)2018
CVE-2018-1318 [HIGH] CVE-2018-1318: trafficserver - Adding method ACLs in remap.config can cause a segfault when the user makes a ca...
Adding method ACLs in remap.config can cause a segfault when the user makes a carefully crafted request. This affects versions Apache Traffic Server (ATS) 6.0.0 to 6.2.2 and 7.0.0 to 7.1.3. To resolve this issue users running 6.x should upgrade to 6.2.3 or later versions and 7.x users should upgrade to 7.1.4 or later versions.
Scope: local
bookworm: resolved (fi
debian
CVE-2025-58136P3HIGHCVSS 7.5fixed in trafficserver 9.2.5+ds-0+deb12u4 (bookworm)2025
CVE-2025-58136 [HIGH] CVE-2025-58136: trafficserver - A bug in POST request handling causes a crash under a certain condition. This i...
A bug in POST request handling causes a crash under a certain condition. This issue affects Apache Traffic Server: from 10.0.0 through 10.1.1, from 9.0.0 through 9.2.12. Users are recommended to upgrade to version 10.1.2 or 9.2.13, which fix the issue. A workaround for older versions is to set proxy.config.http.request_buffer_enabled to 0 (the default value is
debian
CVE-2025-65114P3HIGHCVSS 7.5fixed in trafficserver 9.2.5+ds-0+deb12u4 (bookworm)2025
CVE-2025-65114 [HIGH] CVE-2025-65114: trafficserver - Apache Traffic Server allows request smuggling if chunked messages are malformed...
Apache Traffic Server allows request smuggling if chunked messages are malformed. This issue affects Apache Traffic Server: from 9.0.0 through 9.2.12, from 10.0.0 through 10.1.1. Users are recommended to upgrade to version 9.2.13 or 10.1.2, which fix the issue.
Scope: local
bookworm: resolved (fixed in 9.2.5+ds-0+deb12u4)
bullseye: open
sid: open
debian
CVE-2024-35296P3HIGHCVSS 8.2fixed in trafficserver 9.2.5+ds-0+deb12u1 (bookworm)2024
CVE-2024-35296 [HIGH] CVE-2024-35296: trafficserver - Invalid Accept-Encoding header can cause Apache Traffic Server to fail cache loo...
Invalid Accept-Encoding header can cause Apache Traffic Server to fail cache lookup and force forwarding requests. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.10, from 9.0.0 through 9.2.4. Users are recommended to upgrade to version 8.1.11 or 9.2.5, which fixes the issue.
Scope: local
bookworm: resolved (fixed in 9.2.5+ds-0+deb12u1)
bullse
debian
1 / 4Next →