Skip to main content

Vendor/product archive

apache / traffic_server CVEs

Beta · best-effort

81 CVEs tagged to apache / traffic_server12 Critical, 55 High, 14 Medium, 0 Low, 0 Unrated.

CVE-2025-65114

Published Apr 2, 2026

Apache Traffic Server allows request smuggling if chunked messages are malformed.  This issue affects Apache Traffic Server: from 9.0.0 through 9.2.12, from 10.0.0 through 10.1.1…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-58136

Published Apr 2, 2026

A bug in POST request handling causes a crash under a certain condition. This issue affects Apache Traffic Server: from 10.0.0 through 10.1.1, from 9.0.0 through 9.2.12. Users a…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-49763

Published Jun 19, 2025

ESI plugin does not have the limit for maximum inclusion depth, and that allows excessive memory consumption if malicious instructions are inserted. Users can use a new setting f…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2025-31698

Published Jun 19, 2025

ACL configured in ip_allow.config or remap.config does not use IP addresses that are provided by PROXY protocol. Users can use a new setting (proxy.config.acl.subjects) to choose…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-53868

Published Apr 3, 2025

Apache Traffic Server allows request smuggling if chunked messages are malformed.  This issue affects Apache Traffic Server: from 9.2.0 through 9.2.9, from 10.0.0 through 10.…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-56196

Published Mar 6, 2025

Improper Access Control vulnerability in Apache Traffic Server. This issue affects Apache Traffic Server: from 10.0.0 through 10.0.3. Users are recommended to upgrade to version…

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-56195

Published Mar 6, 2025

Improper Access Control vulnerability in Apache Traffic Server. This issue affects Apache Traffic Server: from 9.2.0 through 9.2.8, from 10.0.0 through 10.0.3. Users are recomme…

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-38311

Published Mar 6, 2025

Improper Input Validation vulnerability in Apache Traffic Server. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.11, from 9.0.0 through 9.2.8, from 10.0.0 throu…

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-56202

Published Mar 6, 2025

Expected Behavior Violation vulnerability in Apache Traffic Server. This issue affects Apache Traffic Server: from 9.0.0 through 9.2.8, from 10.0.0 through 10.0.3. Users are rec…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-50306

Published Nov 14, 2024

Unchecked return value can allow Apache Traffic Server to retain privileges on startup. This issue affects Apache Traffic Server: from 9.2.0 through 9.2.5, from 10.0.0 through 10…

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-50305

Published Nov 14, 2024

Valid Host header field can cause Apache Traffic Server to crash on some platforms. This issue affects Apache Traffic Server: from 9.2.0 through 9.2.5. Users are recommended to…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-38479

Published Nov 14, 2024

Improper Input Validation vulnerability in Apache Traffic Server. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.11, from 9.0.0 through 9.2.5. Users are recomm…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-35296

Published Jul 26, 2024

Invalid Accept-Encoding header can cause Apache Traffic Server to fail cache lookup and force forwarding requests. This issue affects Apache Traffic Server: from 8.0.0 through 8.…

CVSS 8.2 · High
Vendor/product tagsBeta · best-effort

CVE-2024-35161

Published Jul 26, 2024

Apache Traffic Server forwards malformed HTTP chunked trailer section to origin servers. This can be utilized for request smuggling and may also lead cache poisoning if the origin…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2023-38522

Published Jul 26, 2024

Apache Traffic Server accepts characters that are not allowed for HTTP field names and forwards malformed requests to origin servers. This can be utilized for request smuggling an…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2023-33934

Published Aug 9, 2023

Improper Input Validation vulnerability in Apache Software Foundation Apache Traffic Server.This issue affects Apache Traffic Server: through 9.2.1.

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort

CVE-2022-47185

Published Aug 9, 2023

Improper input validation vulnerability on the range header in Apache Software Foundation Apache Traffic Server.This issue affects Apache Traffic Server: through 9.2.1.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2023-33933

Published Jun 14, 2023

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Software Foundation Apache Traffic Server.This issue affects Apache Traffic Server: from 8.0.0 t…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2022-40743

Published Dec 19, 2022

Improper Input Validation vulnerability for the xdebug plugin in Apache Software Foundation Apache Traffic Server can lead to cross site scripting and cache poisoning attacks.This…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-25 of 81 CVEsPage 1 of 4