VendorsApachetraffic_serverall versions
Vulnerabilities

Apache Traffic Server

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

121CVEs
CVE-2026-58181
Apache Traffic Server: uri_signing and url_sig plugins can exhaust the stack or crash
Published 2026-07-29 · Analyzed
8.2EPSS 0.004
CVE-2026-58183
Apache Traffic Server: prefetch plugin can crash on attacker-influenced input
Published 2026-07-29 · Analyzed
8.2EPSS 0.004
CVE-2026-33930
Apache Traffic Server: Buffer overflow via Host field that has a long string value
Published 2026-07-29 · Analyzed
8.2EPSS 0.004
CVE-2026-58189
Apache Traffic Server: Plugins resetting the redirect counter enable SSRF amplification
Published 2026-07-29 · Analyzed
8.2EPSS 0.004
CVE-2026-58158
Apache Traffic Server: PROXY protocol parsing has port truncation and a stack overflow
Published 2026-07-29 · Analyzed
8.2EPSS 0.003
CVE-2026-58159
Apache Traffic Server: Listener and ACL handling allow access-control bypass
Published 2026-07-29 · Analyzed
8.2EPSS 0.003
CVE-2021-38161
Not validating origin TLS certificate
Published 2021-11-03 · Modified
8.1EPSS 0.020
CVE-2021-44759
Improper authentication vulnerability in TLS origin verification
Published 2022-03-23 · Modified
8.1EPSS 0.016
CVE-2019-9515
Some HTTP/2 implementations are vulnerable to a settings flood, potentially leading to a denial of service
Published 2019-08-13 · Modified
7.8EPSS 0.874
CVE-2019-9512
Some HTTP/2 implementations are vulnerable to ping floods, potentially leading to a denial of service
Published 2019-08-13 · Modified
7.8EPSS 0.834
CVE-2019-9514
Some HTTP/2 implementations are vulnerable to a reset flood, potentially leading to a denial of service
Published 2019-08-13 · Modified
7.8EPSS 0.828
CVE-2019-9513
Some HTTP/2 implementations are vulnerable to resource loops, potentially leading to a denial of service
Published 2019-08-13 · Modified
7.8EPSS 0.816
CVE-2019-9511
Some HTTP/2 implementations are vulnerable to window size manipulation and stream prioritization manipulation, potentially leading to a denial of service
Published 2019-08-13 · Modified
7.8EPSS 0.595
CVE-2019-9517
Some HTTP/2 implementations are vulnerable to unconstrained interal data buffering, potentially leading to a denial of service
Published 2019-08-13 · Modified
7.8EPSS 0.279
CVE-2019-9518
Some HTTP/2 implementations are vulnerable to a flood of empty frames, potentially leading to a denial of service
Published 2019-08-13 · Modified
7.8EPSS 0.254
CVE-2016-5396
Apache Traffic Server 6.0.0 to 6.2.0 are affected by an HPACK Bomb Attack.
Published 2017-04-17 · Modified
7.8EPSS 0.029
CVE-2023-44487
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.
Published 2023-10-10 · Analyzed
7.5KEV1 PoCEPSS 1.000
CVE-2024-31309
Apache Traffic Server: HTTP/2 CONTINUATION frames can be utilized for DoS attack
Published 2024-04-10 · Modified
7.5EPSS 0.946
CVE-2019-9516
Some HTTP/2 implementations are vulnerable to a header leak, potentially leading to a denial of service
Published 2019-08-13 · Modified
7.5EPSS 0.563
CVE-2023-39456
Apache Traffic Server: Malformed http/2 frames can cause an abort
Published 2023-10-17 · Modified
7.5EPSS 0.538
CVE-2018-1318
Adding method ACLs in remap.config can cause a segfault when the user makes a carefully crafted request. This affects versions Apache Traffic Server (ATS) 6.0.0 to 6.2.2 and 7.0.0 to 7.1.3. To resolve this issue users running 6.x should upgrade to 6.2.3 or later versions and 7.x users should upgrade to 7.1.4 or later versions.
Published 2018-08-29 · Modified
7.5EPSS 0.077
CVE-2018-8022
A carefully crafted invalid TLS handshake can cause Apache Traffic Server (ATS) to segfault. This affects version 6.2.2. To resolve this issue users running 6.2.2 should upgrade to 6.2.3 or later versions.
Published 2018-08-29 · Modified
7.5EPSS 0.075
CVE-2019-10079
Apache Traffic Server is vulnerable to HTTP/2 setting flood attacks. Earlier versions of Apache Traffic Server didn't limit the number of setting frames sent from the client using the HTTP/2 protocol. Users should upgrade to Apache Traffic Server 7.1.7, 8.0.4, or later versions.
Published 2019-10-22 · Modified
7.5EPSS 0.046
CVE-2020-9494
Apache Traffic Server 6.0.0 to 6.2.3, 7.0.0 to 7.1.10, and 8.0.0 to 8.0.7 is vulnerable to certain types of HTTP/2 HEADERS frames that can cause the server to allocate a large amount of memory and spin the thread.
Published 2020-06-24 · Modified
7.5EPSS 0.040
CVE-2021-27737
Apache Traffic Server 9.0.0 is vulnerable to a remote DOS attack on the experimental Slicer plugin.
Published 2021-05-14 · Modified
7.5EPSS 0.038
CVE-2021-27577
Incorrect handling of url fragment leads to cache poisoning
Published 2021-06-29 · Modified
7.5EPSS 0.035
CVE-2017-5659
Apache Traffic Server before 6.2.1 generates a coredump when there is a mismatch between content length and chunked encoding.
Published 2017-04-17 · Modified
7.5EPSS 0.030
CVE-2021-37148
Request Smuggling - transfer encoding validation
Published 2021-11-03 · Modified
7.5EPSS 0.026
CVE-2021-37149
Request Smuggling - multiple attacks
Published 2021-11-03 · Modified
7.5EPSS 0.026
CVE-2021-37147
Request Smuggling - LF line ending
Published 2021-11-03 · Modified
7.5EPSS 0.025
CVE-2021-32566
Specific sequence of HTTP/2 frames can cause ATS to crash
Published 2021-06-30 · Modified
7.5EPSS 0.025
CVE-2021-41585
ATS stops accepting connections on FreeBSD
Published 2021-11-03 · Modified
7.5EPSS 0.025
CVE-2021-32567
Reading HTTP/2 frames too many times
Published 2021-06-30 · Modified
7.5EPSS 0.024
CVE-2020-9481
Apache ATS 6.0.0 to 6.2.3, 7.0.0 to 7.1.9, and 8.0.0 to 8.0.6 is vulnerable to a HTTP/2 slow read attack.
Published 2020-04-27 · Modified
7.5EPSS 0.024
CVE-2022-31779
Improper HTTP/2 scheme and method validation
Published 2022-08-10 · Modified
7.5EPSS 0.024
CVE-2022-28129
Insufficient Validation of HTTP/1.x Headers
Published 2022-08-10 · Modified
7.5EPSS 0.023
CVE-2022-31780
HTTP/2 framing vulnerabilities
Published 2022-08-10 · Modified
7.5EPSS 0.023
CVE-2017-7671
There is a DOS attack vulnerability in Apache Traffic Server (ATS) 5.2.0 to 5.3.2, 6.0.0 to 6.2.0, and 7.0.0 with the TLS handshake. This issue can cause the server to coredump.
Published 2018-02-27 · Modified
7.5EPSS 0.022
CVE-2021-37150
Protocol vs scheme mismatch
Published 2022-08-10 · Modified
7.5EPSS 0.021
CVE-2021-32565
HTTP Request Smuggling, content length with invalid charters
Published 2021-06-29 · Modified
7.5EPSS 0.021
← Prev2 / 4Next →