VendorsApachetraffic_serverany version
Vulnerabilities

Apache Traffic Server any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

113CVEs
CVE-2026-58159
Apache Traffic Server: Listener and ACL handling allow access-control bypass
Published 2026-07-29 · Analyzed
8.2EPSS 0.006
CVE-2021-38161
Not validating origin TLS certificate
Published 2021-11-03 · Modified
8.1EPSS 0.020
CVE-2021-44759
Improper authentication vulnerability in TLS origin verification
Published 2022-03-23 · Modified
8.1EPSS 0.016
CVE-2019-9515
Some HTTP/2 implementations are vulnerable to a settings flood, potentially leading to a denial of service
Published 2019-08-13 · Modified
7.8EPSS 0.874
CVE-2019-9512
Some HTTP/2 implementations are vulnerable to ping floods, potentially leading to a denial of service
Published 2019-08-13 · Modified
7.8EPSS 0.834
CVE-2019-9514
Some HTTP/2 implementations are vulnerable to a reset flood, potentially leading to a denial of service
Published 2019-08-13 · Modified
7.8EPSS 0.828
CVE-2019-9513
Some HTTP/2 implementations are vulnerable to resource loops, potentially leading to a denial of service
Published 2019-08-13 · Modified
7.8EPSS 0.816
CVE-2019-9511
Some HTTP/2 implementations are vulnerable to window size manipulation and stream prioritization manipulation, potentially leading to a denial of service
Published 2019-08-13 · Modified
7.8EPSS 0.595
CVE-2019-9517
Some HTTP/2 implementations are vulnerable to unconstrained interal data buffering, potentially leading to a denial of service
Published 2019-08-13 · Modified
7.8EPSS 0.279
CVE-2019-9518
Some HTTP/2 implementations are vulnerable to a flood of empty frames, potentially leading to a denial of service
Published 2019-08-13 · Modified
7.8EPSS 0.254
CVE-2023-44487
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.
Published 2023-10-10 · Analyzed
7.5KEV1 PoCEPSS 1.000
CVE-2024-31309
Apache Traffic Server: HTTP/2 CONTINUATION frames can be utilized for DoS attack
Published 2024-04-10 · Modified
7.5EPSS 0.946
CVE-2019-9516
Some HTTP/2 implementations are vulnerable to a header leak, potentially leading to a denial of service
Published 2019-08-13 · Modified
7.5EPSS 0.563
CVE-2023-39456
Apache Traffic Server: Malformed http/2 frames can cause an abort
Published 2023-10-17 · Modified
7.5EPSS 0.538
CVE-2018-1318
Adding method ACLs in remap.config can cause a segfault when the user makes a carefully crafted request. This affects versions Apache Traffic Server (ATS) 6.0.0 to 6.2.2 and 7.0.0 to 7.1.3. To resolve this issue users running 6.x should upgrade to 6.2.3 or later versions and 7.x users should upgrade to 7.1.4 or later versions.
Published 2018-08-29 · Modified
7.5EPSS 0.077
CVE-2018-8022
A carefully crafted invalid TLS handshake can cause Apache Traffic Server (ATS) to segfault. This affects version 6.2.2. To resolve this issue users running 6.2.2 should upgrade to 6.2.3 or later versions.
Published 2018-08-29 · Modified
7.5EPSS 0.075
CVE-2019-10079
Apache Traffic Server is vulnerable to HTTP/2 setting flood attacks. Earlier versions of Apache Traffic Server didn't limit the number of setting frames sent from the client using the HTTP/2 protocol. Users should upgrade to Apache Traffic Server 7.1.7, 8.0.4, or later versions.
Published 2019-10-22 · Modified
7.5EPSS 0.046
CVE-2020-9494
Apache Traffic Server 6.0.0 to 6.2.3, 7.0.0 to 7.1.10, and 8.0.0 to 8.0.7 is vulnerable to certain types of HTTP/2 HEADERS frames that can cause the server to allocate a large amount of memory and spin the thread.
Published 2020-06-24 · Modified
7.5EPSS 0.040
CVE-2021-27577
Incorrect handling of url fragment leads to cache poisoning
Published 2021-06-29 · Modified
7.5EPSS 0.035
CVE-2017-5659
Apache Traffic Server before 6.2.1 generates a coredump when there is a mismatch between content length and chunked encoding.
Published 2017-04-17 · Modified
7.5EPSS 0.030
CVE-2021-37148
Request Smuggling - transfer encoding validation
Published 2021-11-03 · Modified
7.5EPSS 0.026
CVE-2021-37149
Request Smuggling - multiple attacks
Published 2021-11-03 · Modified
7.5EPSS 0.026
CVE-2021-37147
Request Smuggling - LF line ending
Published 2021-11-03 · Modified
7.5EPSS 0.025
CVE-2021-32566
Specific sequence of HTTP/2 frames can cause ATS to crash
Published 2021-06-30 · Modified
7.5EPSS 0.025
CVE-2021-41585
ATS stops accepting connections on FreeBSD
Published 2021-11-03 · Modified
7.5EPSS 0.025
CVE-2021-32567
Reading HTTP/2 frames too many times
Published 2021-06-30 · Modified
7.5EPSS 0.024
CVE-2020-9481
Apache ATS 6.0.0 to 6.2.3, 7.0.0 to 7.1.9, and 8.0.0 to 8.0.6 is vulnerable to a HTTP/2 slow read attack.
Published 2020-04-27 · Modified
7.5EPSS 0.024
CVE-2022-31779
Improper HTTP/2 scheme and method validation
Published 2022-08-10 · Modified
7.5EPSS 0.024
CVE-2022-28129
Insufficient Validation of HTTP/1.x Headers
Published 2022-08-10 · Modified
7.5EPSS 0.023
CVE-2022-31780
HTTP/2 framing vulnerabilities
Published 2022-08-10 · Modified
7.5EPSS 0.023
CVE-2017-7671
There is a DOS attack vulnerability in Apache Traffic Server (ATS) 5.2.0 to 5.3.2, 6.0.0 to 6.2.0, and 7.0.0 with the TLS handshake. This issue can cause the server to coredump.
Published 2018-02-27 · Modified
7.5EPSS 0.022
CVE-2021-37150
Protocol vs scheme mismatch
Published 2022-08-10 · Modified
7.5EPSS 0.021
CVE-2021-32565
HTTP Request Smuggling, content length with invalid charters
Published 2021-06-29 · Modified
7.5EPSS 0.021
CVE-2022-31778
Transfer-Encoding not treated as hop-by-hop
Published 2022-08-10 · Modified
7.5EPSS 0.020
CVE-2020-17508
The ATS ESI plugin has a memory disclosure vulnerability. If you are running the plugin please upgrade. Apache Traffic Server versions 7.0.0 to 7.1.11 and 8.0.0 to 8.1.0 are affected.
Published 2021-01-11 · Modified
7.5EPSS 0.020
CVE-2023-30631
Apache Traffic Server: Configuration option to block the PUSH method in ATS didn't work
Published 2023-06-14 · Modified
7.5EPSS 0.020
CVE-2022-47185
Apache Traffic Server: Invalid Range header causes a crash
Published 2023-08-09 · Modified
7.5EPSS 0.020
CVE-2021-44040
HTTP request line fuzzing attacks
Published 2022-03-23 · Modified
7.5EPSS 0.020
CVE-2022-25763
Improper input validation on HTTP/2 headers
Published 2022-08-10 · Modified
7.5EPSS 0.020
CVE-2018-11783
sslheaders plugin extracts information from the client certificate and sets headers in the request based on the configuration of the plugin. The plugin doesn't strip the headers from the request in some scenarios. This problem was discovered in versions 6.0.0 to 6.0.3, 7.0.0 to 7.1.5, and 8.0.0 to 8.0.1.
Published 2019-03-07 · Modified
7.5EPSS 0.019
← Prev2 / 3Next →