← Back to Products

traffic_server

Vendor: apache

4
Total CVEs
0
Critical
1
High
2
Medium
1
Low

Recent CVEs

Apache Traffic Server allows request smuggling if chunked messages are malformed.  This issue affects Apache Traffic Server: from 9.0.0 through 9.2.12, from 10.0.0 through 10.1.1. Users are recomme...

Affected versions: 10.0.0 10.0.1 10.0.2 10.0.3 10.0.4 +22 more

Published: Apr 2, 2026

7.5

CVSS

A bug in POST request handling causes a crash under a certain condition. This issue affects Apache Traffic Server: from 10.0.0 through 10.1.1, from 9.0.0 through 9.2.12. Users are recommended to upg...

Affected versions: 10.0.0 10.0.1 10.0.2 10.0.3 10.0.4 +22 more

Published: Apr 2, 2026

7.5

CVSS

ESI plugin does not have the limit for maximum inclusion depth, and that allows excessive memory consumption if malicious instructions are inserted. Users can use a new setting for the plugin (--max-...

Affected versions: 10.0.0 10.0.1 10.0.2 10.0.3 10.0.4 +20 more

Published: Jun 19, 2025

7.5

CVSS

ACL configured in ip_allow.config or remap.config does not use IP addresses that are provided by PROXY protocol. Users can use a new setting (proxy.config.acl.subjects) to choose which IP addresses t...

Affected versions: 10.0.0 10.0.1 10.0.2 10.0.3 10.0.4 +20 more

Published: Jun 19, 2025

7.5

CVSS

Apache Traffic Server allows request smuggling if chunked messages are malformed.  This issue affects Apache Traffic Server: from 9.2.0 through 9.2.9, from 10.0.0 through 10.0.4. Users are reco...

Affected versions: 10.0.0 10.0.1 10.0.2 10.0.3 10.0.4 +18 more

Published: Apr 3, 2025

7.5

CVSS

Improper Access Control vulnerability in Apache Traffic Server. This issue affects Apache Traffic Server: from 10.0.0 through 10.0.3. Users are recommended to upgrade to version 10.0.4, which fixes ...

Affected versions: 10.0.0 10.0.1 10.0.2 10.0.3

Published: Mar 6, 2025

6.3

CVSS

Improper Access Control vulnerability in Apache Traffic Server. This issue affects Apache Traffic Server: from 9.2.0 through 9.2.8, from 10.0.0 through 10.0.3. Users are recommended to upgrade to ve...

Affected versions: 10.0.0 10.0.1 10.0.2 10.0.3 9.0.0 +16 more

Published: Mar 6, 2025

6.3

CVSS

Improper Input Validation vulnerability in Apache Traffic Server. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.11, from 9.0.0 through 9.2.8, from 10.0.0 through 10.0.3. Users are...

Affected versions: 10.0.0 10.0.1 10.0.2 10.0.3 9.0.0 +16 more

Published: Mar 6, 2025

6.3

CVSS

Expected Behavior Violation vulnerability in Apache Traffic Server. This issue affects Apache Traffic Server: from 9.0.0 through 9.2.8, from 10.0.0 through 10.0.3. Users are recommended to upgrade t...

Affected versions: 10.0.0 10.0.1 10.0.2 10.0.3 9.0.0 +16 more

Published: Mar 6, 2025

4.3

CVSS

In bta_hd_set_report_act of bta_hd_act.cc, there is a possible out-of-bounds read due to an integer overflow. This could lead to remote information disclosure in the Bluetooth service with no addition...

Affected versions: 6.0.0 6.0.3 6.1.0 6.1.1 6.2.0 +21 more

Published: Nov 20, 2024

6.5

CVSS

Unchecked return value can allow Apache Traffic Server to retain privileges on startup. This issue affects Apache Traffic Server: from 9.2.0 through 9.2.5, from 10.0.0 through 10.0.1. Users are reco...

Affected versions: 10.0.0 10.0.1 9.0.0 9.0.1 9.0.2 +11 more

Published: Nov 14, 2024

9.1

CVSS

Valid Host header field can cause Apache Traffic Server to crash on some platforms. This issue affects Apache Traffic Server: from 9.2.0 through 9.2.5. Users are recommended to upgrade to version 9....

Affected versions: 9.0.0 9.0.1 9.0.2 9.1.0 9.1.1 +9 more

Published: Nov 14, 2024

7.5

CVSS

Improper Input Validation vulnerability in Apache Traffic Server. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.11, from 9.0.0 through 9.2.5. Users are recommended to upgrade to v...

Affected versions: 8.0.0 8.0.1 8.0.2 8.0.3 8.0.4 +30 more

Published: Nov 14, 2024

7.5

CVSS

Invalid Accept-Encoding header can cause Apache Traffic Server to fail cache lookup and force forwarding requests. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.10, from 9.0.0 thro...

Affected versions: 8.0.0 8.0.1 8.0.2 8.0.3 8.0.4 +28 more

Published: Jul 26, 2024

8.2

CVSS

Apache Traffic Server forwards malformed HTTP chunked trailer section to origin servers. This can be utilized for request smuggling and may also lead cache poisoning if the origin servers are vulnerab...

Affected versions: 8.0.0 8.0.1 8.0.2 8.0.3 8.0.4 +28 more

Published: Jul 26, 2024

7.5

CVSS

Apache Traffic Server accepts characters that are not allowed for HTTP field names and forwards malformed requests to origin servers. This can be utilized for request smuggling and may also lead cache...

Affected versions: 8.0.0 8.0.1 8.0.2 8.0.3 8.0.4 +28 more

Published: Jul 26, 2024

7.5

CVSS

HTTP/2 CONTINUATION DoS attack can cause Apache Traffic Server to consume more resources on the server.  Version from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.3 are affected. Users can set a ne...

Affected versions: 8.0.0 8.0.1 8.0.2 8.0.3 8.0.4 +26 more

Published: Apr 10, 2024

7.5

CVSS

Apache Traffic Server is vulnerable to HTTP/2 setting flood attacks. Earlier versions of Apache Traffic Server didn't limit the number of setting frames sent from the client using the HTTP/2 protocol....

Affected versions: 2.0.0 2.0.1 2.1.0 2.1.1 2.1.2 +70 more

Published: Oct 22, 2019

7.5

CVSS

Some HTTP/2 implementations are vulnerable to a flood of empty frames, potentially leading to a denial of service. The attacker sends a stream of frames with an empty payload and without the end-of-st...

Affected versions: 6.0.0 6.0.3 6.1.0 6.1.1 6.2.0 +15 more

Published: Aug 13, 2019

7.5

CVSS

Some HTTP/2 implementations are vulnerable to unconstrained interal data buffering, potentially leading to a denial of service. The attacker opens the HTTP/2 window so the peer can send without constr...

Affected versions: 6.0.0 6.0.3 6.1.0 6.1.1 6.2.0 +15 more

Published: Aug 13, 2019

7.5

CVSS

Some HTTP/2 implementations are vulnerable to a header leak, potentially leading to a denial of service. The attacker sends a stream of headers with a 0-length header name and 0-length header value, o...

Affected versions: 6.0.0 6.0.3 6.1.0 6.1.1 6.2.0 +15 more

Published: Aug 13, 2019

6.5

CVSS

Some HTTP/2 implementations are vulnerable to a settings flood, potentially leading to a denial of service. The attacker sends a stream of SETTINGS frames to the peer. Since the RFC requires that the ...

Affected versions: 6.0.0 6.0.3 6.1.0 6.1.1 6.2.0 +15 more

Published: Aug 13, 2019

7.5

CVSS

Some HTTP/2 implementations are vulnerable to a reset flood, potentially leading to a denial of service. The attacker opens a number of streams and sends an invalid request over each stream that shoul...

Affected versions: 6.0.0 6.0.3 6.1.0 6.1.1 6.2.0 +15 more

Published: Aug 13, 2019

7.5

CVSS

Some HTTP/2 implementations are vulnerable to resource loops, potentially leading to a denial of service. The attacker creates multiple request streams and continually shuffles the priority of the str...

Affected versions: 6.0.0 6.0.3 6.1.0 6.1.1 6.2.0 +15 more

Published: Aug 13, 2019

7.5

CVSS

Some HTTP/2 implementations are vulnerable to ping floods, potentially leading to a denial of service. The attacker sends continual pings to an HTTP/2 peer, causing the peer to build an internal queue...

Affected versions: 6.0.0 6.0.3 6.1.0 6.1.1 6.2.0 +15 more

Published: Aug 13, 2019

7.5

CVSS

Some HTTP/2 implementations are vulnerable to window size manipulation and stream prioritization manipulation, potentially leading to a denial of service. The attacker requests a large amount of data ...

Affected versions: 6.0.0 6.0.3 6.1.0 6.1.1 6.2.0 +15 more

Published: Aug 13, 2019

7.5

CVSS

There is a DOS attack vulnerability in Apache Traffic Server (ATS) 5.2.0 to 5.3.2, 6.0.0 to 6.2.0, and 7.0.0 with the TLS handshake. This issue can cause the server to coredump....

Affected versions: 5.2.0 5.2.1 5.3.0 5.3.1 5.3.2 +5 more

Published: Feb 27, 2018

5.0

CVSS

There is a vulnerability in Apache Traffic Server (ATS) 6.2.0 and prior and 7.0.0 and prior with the Host header and line folding. This can have issues when interacting with upstream proxies and the w...

Affected versions: 2.0.0 2.0.1 2.1.0 2.1.1 2.1.2 +58 more

Published: Feb 27, 2018

5.0

CVSS

The HTTP/2 experimental feature in Apache Traffic Server 5.3.x before 5.3.1 allows remote attackers to cause a denial of service (out-of-bounds access and daemon crash) or possibly execute arbitrary c...

Affected versions: 5.3.0

Published: Oct 30, 2017

7.5

CVSS

Apache Traffic Server 5.1.x before 5.1.1 allows remote attackers to bypass access restrictions by leveraging failure to properly tunnel remap requests using CONNECT....

Affected versions: 5.1.0

Published: Oct 30, 2017

7.5

CVSS

Unspecified vulnerability in the HTTP/2 experimental feature in Apache Traffic Server before 5.3.x before 5.3.2 has unknown impact and attack vectors, a different vulnerability than CVE-2015-5168....

Affected versions: 5.3.0 5.3.1

Published: Sep 13, 2017

10.0

CVSS

Unspecified vulnerability in the HTTP/2 experimental feature in Apache Traffic Server 5.3.x before 5.3.2 has unknown impact and attack vectors, a different vulnerability than CVE-2015-5206....

Affected versions: 5.3.0 5.3.1

Published: Sep 13, 2017

10.0

CVSS

Apache Traffic Server before 6.2.1 generates a coredump when there is a mismatch between content length and chunked encoding....

Affected versions: 2.0.0 2.0.1 2.1.0 2.1.1 2.1.2 +55 more

Published: Apr 17, 2017

5.0

CVSS

Apache Traffic Server 6.0.0 to 6.2.0 are affected by an HPACK Bomb Attack....

Affected versions: 6.0.0 6.1.0 6.1.1 6.2.0

Published: Apr 17, 2017

7.8

CVSS

Apache Traffic Server before 5.1.2 allows remote attackers to cause a denial of service via unspecified vectors, related to internal buffer sizing....

Affected versions: 2.0.0 2.0.1 2.1.0 2.1.1 2.1.2 +44 more

Published: Jan 13, 2015

5.0

CVSS

Unspecified vulnerability in Apache Traffic Server 3.x through 3.2.5, 4.x before 4.2.1.1, and 5.x before 5.0.1 has unknown impact and attack vectors, possibly related to health checks....

Affected versions: 2.0.0 2.0.1 2.1.0 2.1.1 2.1.2 +29 more

Published: Aug 22, 2014

10.0

CVSS

Apache Traffic Server 2.0.x and 3.0.x before 3.0.4 and 3.1.x before 3.1.3 does not properly allocate heap memory, which allows remote attackers to cause a denial of service (daemon crash) via a long H...

Affected versions: 2.0.0 2.0.1 2.1.0 2.1.1 2.1.2 +14 more

Published: Mar 26, 2012

5.0

CVSS

Apache Traffic Server before 2.0.1, and 2.1.x before 2.1.2-unstable, does not properly choose DNS source ports and transaction IDs, and does not properly use DNS query fields to validate responses, wh...

Affected versions: 2.0.0 2.1.0 2.1.1

Published: Sep 13, 2010

4.3

CVSS

Buffer overflow in traffic_manager for Inktomi Traffic Server 4.0.18 through 5.2.2, Traffic Edge 1.1.2 and 1.5.0, and Media-IXT 3.0.4 allows local users to gain root privileges via a long -path argume...

Affected versions: 4.0.18 4.0.20 5.1.3 5.2.0r 5.2.1 +1 more

Published: Oct 4, 2002

7.2

CVSS