VendorsApachetraffic_serverall versions
Vulnerabilities

Apache Traffic Server

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

121CVEs
CVE-2022-31778
Transfer-Encoding not treated as hop-by-hop
Published 2022-08-10 · Modified
7.5EPSS 0.020
CVE-2020-17508
The ATS ESI plugin has a memory disclosure vulnerability. If you are running the plugin please upgrade. Apache Traffic Server versions 7.0.0 to 7.1.11 and 8.0.0 to 8.1.0 are affected.
Published 2021-01-11 · Modified
7.5EPSS 0.020
CVE-2023-30631
Apache Traffic Server: Configuration option to block the PUSH method in ATS didn't work
Published 2023-06-14 · Modified
7.5EPSS 0.020
CVE-2022-47185
Apache Traffic Server: Invalid Range header causes a crash
Published 2023-08-09 · Modified
7.5EPSS 0.020
CVE-2021-44040
HTTP request line fuzzing attacks
Published 2022-03-23 · Modified
7.5EPSS 0.020
CVE-2022-25763
Improper input validation on HTTP/2 headers
Published 2022-08-10 · Modified
7.5EPSS 0.020
CVE-2018-11783
sslheaders plugin extracts information from the client certificate and sets headers in the request based on the configuration of the plugin. The plugin doesn't strip the headers from the request in some scenarios. This problem was discovered in versions 6.0.0 to 6.0.3, 7.0.0 to 7.1.5, and 8.0.0 to 8.0.1.
Published 2019-03-07 · Modified
7.5EPSS 0.019
CVE-2020-17509
ATS negative cache option is vulnerable to a cache poisoning attack. If you have this option enabled, please upgrade or disable this feature. Apache Traffic Server versions 7.0.0 to 7.1.11 and 8.0.0 to 8.1.0 are affected.
Published 2021-01-11 · Modified
7.5EPSS 0.018
CVE-2022-47184
Apache Traffic Server: The TRACE method can be use to disclose network information
Published 2023-06-14 · Modified
7.5EPSS 0.015
CVE-2023-33933
Apache Traffic Server: s3_auth plugin problem with hash calculation
Published 2023-06-14 · Modified
7.5EPSS 0.015
CVE-2022-32749
Apache Traffic Server: Improperly handled requests can cause crashes in specific plugins
Published 2022-12-19 · Modified
7.5EPSS 0.013
CVE-2023-41752
Apache Traffic Server: s3_auth plugin problem with hash calculation
Published 2023-10-17 · Modified
7.5EPSS 0.012
CVE-2023-38522
Apache Traffic Server: Incomplete field name check allows request smuggling
Published 2024-07-26 · Modified
7.5EPSS 0.010
CVE-2024-50305
Apache Traffic Server: Valid Host field value can cause crashes
Published 2024-11-14 · Analyzed
7.5EPSS 0.009
CVE-2024-38479
Apache Traffic Server: Cache key plugin is vulnerable to cache poisoning attack
Published 2024-11-14 · Modified
7.5EPSS 0.008
CVE-2025-49763
Apache Traffic Server: Remote DoS via memory exhaustion in ESI Plugin
Published 2025-06-19 · Analyzed
7.5EPSS 0.007
CVE-2026-59173
Apache Traffic Server: DoS vulnerability in HTTP/2 via stalled flow-control conditions
Published 2026-07-18 · Analyzed
7.5EPSS 0.007
CVE-2025-58136
Apache Traffic Server: A simple legitimate POST request causes a crash
Published 2026-04-02 · Analyzed
7.5EPSS 0.007
CVE-2024-53868
Apache Traffic Server: Malformed chunked message body allows request smuggling
Published 2025-04-03 · Analyzed
7.5EPSS 0.006
CVE-2025-31698
Apache Traffic Server: Client IP address from PROXY protocol is not used for ACL
Published 2025-06-19 · Analyzed
7.5EPSS 0.006
CVE-2025-65114
Apache Traffic Server: Malformed chunked message body allows request smuggling
Published 2026-04-02 · Analyzed
7.5EPSS 0.004
CVE-2026-58187
Apache Traffic Server: Multiplexer plugin chunk decoder enables a denial of service
Published 2026-07-29 · Analyzed
7.5EPSS 0.003
CVE-2026-24033
Apache Traffic Server: Request smuggling via chunked extension quoted-string parsing
Published 2026-07-29 · Analyzed
7.2EPSS 0.003
CVE-2026-58152
Apache Traffic Server: Integer-handling errors in HPACK/XPACK decoding corrupt memory
Published 2026-07-29 · Analyzed
6.9EPSS 0.003
CVE-2018-8004
There are multiple HTTP smuggling and cache poisoning issues when clients making malicious requests interact with Apache Traffic Server (ATS). This affects versions 6.0.0 to 6.2.2 and 7.0.0 to 7.1.3. To resolve this issue users running 6.x should upgrade to 6.2.3 or later versions and 7.x users should upgrade to 7.1.4 or later versions.
Published 2018-08-29 · Modified
6.5EPSS 0.063
CVE-2026-58160
Apache Traffic Server: Out-of-bounds reads while parsing DNS responses
Published 2026-07-29 · Analyzed
6.5EPSS 0.004
CVE-2018-9481
In bta_hd_set_report_act of bta_hd_act.cc, there is a possible out-of-bounds read due to an integer overflow. This could lead to remote information disclosure in the Bluetooth service with no additional execution privileges needed. User interaction is not needed for exploitation.
Published 2024-11-20 · Analyzed
6.5EPSS 0.001
CVE-2024-38311
Apache Traffic Server: Request smuggling via pipelining after a chunked message body
Published 2025-03-06 · Analyzed
6.3EPSS 0.009
CVE-2024-56195
Apache Traffic Server: Intercept plugins are not access controlled
Published 2025-03-06 · Analyzed
6.3EPSS 0.008
CVE-2024-56196
Apache Traffic Server: ACL is not fully compatible with older versions
Published 2025-03-06 · Analyzed
6.3EPSS 0.008
CVE-2026-65100
Apache Traffic Server: HPACK encoder desynchronizes from the decoder after a failed header encode
Published 2026-07-29 · Analyzed
6.3EPSS 0.004
CVE-2026-58156
Apache Traffic Server: URL and port parsing errors allow access-control bypass
Published 2026-07-29 · Analyzed
6.3EPSS 0.002
CVE-2026-65325
Apache Traffic Server: HTTP/2 multiplexed origin sessions are reused without certificate re-verification
Published 2026-07-29 · Analyzed
6.3EPSS 0.002
CVE-2022-40743
Apache Traffic Server: Security issues with the xdebug plugin
Published 2022-12-19 · Modified
6.1EPSS 0.011
CVE-2018-8040
Pages that are rendered using the ESI plugin can have access to the cookie header when the plugin is configured not to allow access. This affects Apache Traffic Server (ATS) versions 6.0.0 to 6.2.2 and 7.0.0 to 7.1.3. To resolve this issue users running 6.x should upgrade to 6.2.3 or later versions and 7.x users should upgrade to 7.1.4 or later versions.
Published 2018-08-29 · Modified
5.3EPSS 0.072
CVE-2018-8005
When there are multiple ranges in a range request, Apache Traffic Server (ATS) will read the entire object from cache. This can cause performance problems with large objects in cache. This affects versions 6.0.0 to 6.2.2 and 7.0.0 to 7.1.3. To resolve this issue users running 6.x users should upgrade to 6.2.3 or later versions and 7.x users should upgrade to 7.1.4 or later versions.
Published 2018-08-29 · Modified
5.3EPSS 0.069
CVE-2022-37392
Apache Traffic Server: Improperly reading the client requests
Published 2022-12-19 · Modified
5.3EPSS 0.011
CVE-2014-10022
Apache Traffic Server before 5.1.2 allows remote attackers to cause a denial of service via unspecified vectors, related to internal buffer sizing.
Published 2015-01-13 · Modified
5.0EPSS 0.056
CVE-2012-0256
Apache Traffic Server 2.0.x and 3.0.x before 3.0.4 and 3.1.x before 3.1.3 does not properly allocate heap memory, which allows remote attackers to cause a denial of service (daemon crash) via a long HTTP Host header.
Published 2012-03-26 · Modified
5.0EPSS 0.034
CVE-2010-2952
Apache Traffic Server before 2.0.1, and 2.1.x before 2.1.2-unstable, does not properly choose DNS source ports and transaction IDs, and does not properly use DNS query fields to validate responses, which makes it easier for man-in-the-middle attackers to poison the internal DNS cache via a crafted response.
Published 2010-09-13 · Modified
4.3EPSS 0.026
← Prev3 / 4Next →