cbcvebase.

Debian Trafficserver vulnerabilities

73 known vulnerabilities affecting debian/trafficserver.

Total CVEs
73
CISA KEV
1
actively exploited
Public exploits
1
Exploited in wild
1
Severity breakdown
CRITICAL11HIGH51MEDIUM10LOW1

Vulnerabilities

Page 2 of 4
CVE-2022-25763P3HIGHCVSS 7.5fixed in trafficserver 9.1.3+ds-1 (bookworm)2022
CVE-2022-25763 [HIGH] CVE-2022-25763: trafficserver - Improper Input Validation vulnerability in HTTP/2 request validation of Apache T... Improper Input Validation vulnerability in HTTP/2 request validation of Apache Traffic Server allows an attacker to create smuggle or cache poison attacks. This issue affects Apache Traffic Server 8.0.0 to 9.1.2. Scope: local bookworm: resolved (fixed in 9.1.3+ds-1) bullseye: resolved (fixed in 8.1.5+ds-1~deb11u1) sid: resolved (fixed in 9.1.3+ds-1)
debian
CVE-2024-53868P3HIGHCVSS 7.5fixed in trafficserver 9.2.5+ds-0+deb12u3 (bookworm)2024
CVE-2024-53868 [HIGH] CVE-2024-53868: trafficserver - Apache Traffic Server allows request smuggling if chunked messages are malformed... Apache Traffic Server allows request smuggling if chunked messages are malformed. This issue affects Apache Traffic Server: from 9.2.0 through 9.2.9, from 10.0.0 through 10.0.4. Users are recommended to upgrade to version 9.2.10 or 10.0.5, which fixes the issue. Scope: local bookworm: resolved (fixed in 9.2.5+ds-0+deb12u3) bullseye: open sid: open
debian
CVE-2025-31698P3HIGHCVSS 7.5fixed in trafficserver 9.2.5+ds-0+deb12u3 (bookworm)2025
CVE-2025-31698 [HIGH] CVE-2025-31698: trafficserver - ACL configured in ip_allow.config or remap.config does not use IP addresses that... ACL configured in ip_allow.config or remap.config does not use IP addresses that are provided by PROXY protocol. Users can use a new setting (proxy.config.acl.subjects) to choose which IP addresses to use for the ACL if Apache Traffic Server is configured to accept PROXY protocol. This issue affects undefined: from 10.0.0 through 10.0.6, from 9.0.0 through 9.2
debian
CVE-2021-38161P3HIGHCVSS 8.1fixed in trafficserver 9.1.0+ds-1 (bookworm)2021
CVE-2021-38161 [HIGH] CVE-2021-38161: trafficserver - Improper Authentication vulnerability in TLS origin verification of Apache Traff... Improper Authentication vulnerability in TLS origin verification of Apache Traffic Server allows for man in the middle attacks. This issue affects Apache Traffic Server 8.0.0 to 8.0.8. Scope: local bookworm: resolved (fixed in 9.1.0+ds-1) bullseye: resolved (fixed in 8.1.1+ds-1.1+deb11u1) sid: resolved (fixed in 9.1.0+ds-1)
debian
CVE-2021-44759P3HIGHCVSS 8.1fixed in trafficserver 9.1.0+ds-1 (bookworm)2021
CVE-2021-44759 [HIGH] CVE-2021-44759: trafficserver - Improper Authentication vulnerability in TLS origin validation of Apache Traffic... Improper Authentication vulnerability in TLS origin validation of Apache Traffic Server allows an attacker to create a man in the middle attack. This issue affects Apache Traffic Server 8.0.0 to 8.1.0. Scope: local bookworm: resolved (fixed in 9.1.0+ds-1) bullseye: resolved (fixed in 8.1.1+ds-1.1+deb11u1) sid: resolved (fixed in 9.1.0+ds-1)
debian
CVE-2021-44040P3HIGHCVSS 7.5fixed in trafficserver 9.1.2+ds-1 (bookworm)2021
CVE-2021-44040 [HIGH] CVE-2021-44040: trafficserver - Improper Input Validation vulnerability in request line parsing of Apache Traffi... Improper Input Validation vulnerability in request line parsing of Apache Traffic Server allows an attacker to send invalid requests. This issue affects Apache Traffic Server 8.0.0 to 8.1.3 and 9.0.0 to 9.1.1. Scope: local bookworm: resolved (fixed in 9.1.2+ds-1) bullseye: resolved (fixed in 8.1.1+ds-1.1+deb11u1) sid: resolved (fixed in 9.1.2+ds-1)
debian
CVE-2022-31779P3HIGHCVSS 7.5fixed in trafficserver 9.1.3+ds-1 (bookworm)2022
CVE-2022-31779 [HIGH] CVE-2022-31779: trafficserver - Improper Input Validation vulnerability in HTTP/2 header parsing of Apache Traff... Improper Input Validation vulnerability in HTTP/2 header parsing of Apache Traffic Server allows an attacker to smuggle requests. This issue affects Apache Traffic Server 8.0.0 to 9.1.2. Scope: local bookworm: resolved (fixed in 9.1.3+ds-1) bullseye: resolved (fixed in 8.1.5+ds-1~deb11u1) sid: resolved (fixed in 9.1.3+ds-1)
debian
CVE-2021-37150P3HIGHCVSS 7.5fixed in trafficserver 9.1.3+ds-1 (bookworm)2021
CVE-2021-37150 [HIGH] CVE-2021-37150: trafficserver - Improper Input Validation vulnerability in header parsing of Apache Traffic Serv... Improper Input Validation vulnerability in header parsing of Apache Traffic Server allows an attacker to request secure resources. This issue affects Apache Traffic Server 8.0.0 to 9.1.2. Scope: local bookworm: resolved (fixed in 9.1.3+ds-1) bullseye: resolved (fixed in 8.1.5+ds-1~deb11u1) sid: resolved (fixed in 9.1.3+ds-1)
debian
CVE-2017-5660P3HIGHCVSS 8.6fixed in trafficserver 7.1.2+ds-1 (bookworm)2017
CVE-2017-5660 [HIGH] CVE-2017-5660: trafficserver - There is a vulnerability in Apache Traffic Server (ATS) 6.2.0 and prior and 7.0.... There is a vulnerability in Apache Traffic Server (ATS) 6.2.0 and prior and 7.0.0 and prior with the Host header and line folding. This can have issues when interacting with upstream proxies and the wrong host being used. Scope: local bookworm: resolved (fixed in 7.1.2+ds-1) bullseye: resolved (fixed in 7.1.2+ds-1) sid: resolved (fixed in 7.1.2+ds-1)
debian
CVE-2021-27577P3HIGHCVSS 7.5fixed in trafficserver 8.1.1+ds-1.1 (bookworm)2021
CVE-2021-27577 [HIGH] CVE-2021-27577: trafficserver - Incorrect handling of url fragment vulnerability of Apache Traffic Server allows... Incorrect handling of url fragment vulnerability of Apache Traffic Server allows an attacker to poison the cache. This issue affects Apache Traffic Server 7.0.0 to 7.1.12, 8.0.0 to 8.1.1, 9.0.0 to 9.0.1. Scope: local bookworm: resolved (fixed in 8.1.1+ds-1.1) bullseye: resolved (fixed in 8.1.1+ds-1.1) sid: resolved (fixed in 8.1.1+ds-1.1)
debian
CVE-2023-30631P3HIGHCVSS 7.5fixed in trafficserver 9.2.0+ds-2+deb12u1 (bookworm)2023
CVE-2023-30631 [HIGH] CVE-2023-30631: trafficserver - Improper Input Validation vulnerability in Apache Software Foundation Apache Tra... Improper Input Validation vulnerability in Apache Software Foundation Apache Traffic Server. The configuration option proxy.config.http.push_method_enabled didn't function. However, by default the PUSH method is blocked in the ip_allow configuration file.This issue affects Apache Traffic Server: from 8.0.0 through 9.2.0. 8.x users should upgrade to 8.1.7 or la
debian
CVE-2022-28129P3HIGHCVSS 7.5fixed in trafficserver 9.1.3+ds-1 (bookworm)2022
CVE-2022-28129 [HIGH] CVE-2022-28129: trafficserver - Improper Input Validation vulnerability in HTTP/1.1 header parsing of Apache Tra... Improper Input Validation vulnerability in HTTP/1.1 header parsing of Apache Traffic Server allows an attacker to send invalid headers. This issue affects Apache Traffic Server 8.0.0 to 9.1.2. Scope: local bookworm: resolved (fixed in 9.1.3+ds-1) bullseye: resolved (fixed in 8.1.5+ds-1~deb11u1) sid: resolved (fixed in 9.1.3+ds-1)
debian
CVE-2022-31780P3HIGHCVSS 7.5fixed in trafficserver 9.1.3+ds-1 (bookworm)2022
CVE-2022-31780 [HIGH] CVE-2022-31780: trafficserver - Improper Input Validation vulnerability in HTTP/2 frame handling of Apache Traff... Improper Input Validation vulnerability in HTTP/2 frame handling of Apache Traffic Server allows an attacker to smuggle requests. This issue affects Apache Traffic Server 8.0.0 to 9.1.2. Scope: local bookworm: resolved (fixed in 9.1.3+ds-1) bullseye: resolved (fixed in 8.1.5+ds-1~deb11u1) sid: resolved (fixed in 9.1.3+ds-1)
debian
CVE-2018-8022P3HIGHCVSS 7.5fixed in trafficserver 7.0.0-1 (bookworm)2018
CVE-2018-8022 [HIGH] CVE-2018-8022: trafficserver - A carefully crafted invalid TLS handshake can cause Apache Traffic Server (ATS) ... A carefully crafted invalid TLS handshake can cause Apache Traffic Server (ATS) to segfault. This affects version 6.2.2. To resolve this issue users running 6.2.2 should upgrade to 6.2.3 or later versions. Scope: local bookworm: resolved (fixed in 7.0.0-1) bullseye: resolved (fixed in 7.0.0-1) sid: resolved (fixed in 7.0.0-1)
debian
CVE-2023-38522P3HIGHCVSS 7.5fixed in trafficserver 9.2.5+ds-0+deb12u1 (bookworm)2023
CVE-2023-38522 [HIGH] CVE-2023-38522: trafficserver - Apache Traffic Server accepts characters that are not allowed for HTTP field nam... Apache Traffic Server accepts characters that are not allowed for HTTP field names and forwards malformed requests to origin servers. This can be utilized for request smuggling and may also lead cache poisoning if the origin servers are vulnerable. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.10, from 9.0.0 through 9.2.4. Users are recommen
debian
CVE-2024-35161P3HIGHCVSS 7.5fixed in trafficserver 9.2.5+ds-0+deb12u1 (bookworm)2024
CVE-2024-35161 [HIGH] CVE-2024-35161: trafficserver - Apache Traffic Server forwards malformed HTTP chunked trailer section to origin ... Apache Traffic Server forwards malformed HTTP chunked trailer section to origin servers. This can be utilized for request smuggling and may also lead cache poisoning if the origin servers are vulnerable. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.10, from 9.0.0 through 9.2.4. Users can set a new setting (proxy.config.http.drop_chunked_tra
debian
CVE-2024-38479P3HIGHCVSS 7.5fixed in trafficserver 9.2.5+ds-0+deb12u2 (bookworm)2024
CVE-2024-38479 [HIGH] CVE-2024-38479: trafficserver - Improper Input Validation vulnerability in Apache Traffic Server. This issue af... Improper Input Validation vulnerability in Apache Traffic Server. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.11, from 9.0.0 through 9.2.5. Users are recommended to upgrade to version 9.2.6, which fixes the issue, or 10.0.2, which does not have the issue. Scope: local bookworm: resolved (fixed in 9.2.5+ds-0+deb12u2) bullseye: resolved (fix
debian
CVE-2021-37149P3HIGHCVSS 7.5fixed in trafficserver 9.1.1+ds-1 (bookworm)2021
CVE-2021-37149 [HIGH] CVE-2021-37149: trafficserver - Improper Input Validation vulnerability in header parsing of Apache Traffic Serv... Improper Input Validation vulnerability in header parsing of Apache Traffic Server allows an attacker to smuggle requests. This issue affects Apache Traffic Server 8.0.0 to 8.1.2 and 9.0.0 to 9.1.0. Scope: local bookworm: resolved (fixed in 9.1.1+ds-1) bullseye: resolved (fixed in 8.1.1+ds-1.1+deb11u1) sid: resolved (fixed in 9.1.1+ds-1)
debian
CVE-2021-37148P3HIGHCVSS 7.5fixed in trafficserver 9.1.1+ds-1 (bookworm)2021
CVE-2021-37148 [HIGH] CVE-2021-37148: trafficserver - Improper input validation vulnerability in header parsing of Apache Traffic Serv... Improper input validation vulnerability in header parsing of Apache Traffic Server allows an attacker to smuggle requests. This issue affects Apache Traffic Server 8.0.0 to 8.1.2 and 9.0.0 to 9.0.1. Scope: local bookworm: resolved (fixed in 9.1.1+ds-1) bullseye: resolved (fixed in 8.1.1+ds-1.1+deb11u1) sid: resolved (fixed in 9.1.1+ds-1)
debian
CVE-2021-37147P3HIGHCVSS 7.5fixed in trafficserver 9.1.1+ds-1 (bookworm)2021
CVE-2021-37147 [HIGH] CVE-2021-37147: trafficserver - Improper input validation vulnerability in header parsing of Apache Traffic Serv... Improper input validation vulnerability in header parsing of Apache Traffic Server allows an attacker to smuggle requests. This issue affects Apache Traffic Server 8.0.0 to 8.1.2 and 9.0.0 to 9.1.0. Scope: local bookworm: resolved (fixed in 9.1.1+ds-1) bullseye: resolved (fixed in 8.1.1+ds-1.1+deb11u1) sid: resolved (fixed in 9.1.1+ds-1)
debian
Debian Trafficserver vulnerabilities | cvebase