VendorsApachetraffic_serverany version
Vulnerabilities

Apache Traffic Server any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

113CVEs
CVE-2020-17509
ATS negative cache option is vulnerable to a cache poisoning attack. If you have this option enabled, please upgrade or disable this feature. Apache Traffic Server versions 7.0.0 to 7.1.11 and 8.0.0 to 8.1.0 are affected.
Published 2021-01-11 · Modified
7.5EPSS 0.018
CVE-2022-47184
Apache Traffic Server: The TRACE method can be use to disclose network information
Published 2023-06-14 · Modified
7.5EPSS 0.015
CVE-2023-33933
Apache Traffic Server: s3_auth plugin problem with hash calculation
Published 2023-06-14 · Modified
7.5EPSS 0.015
CVE-2022-32749
Apache Traffic Server: Improperly handled requests can cause crashes in specific plugins
Published 2022-12-19 · Modified
7.5EPSS 0.013
CVE-2023-41752
Apache Traffic Server: s3_auth plugin problem with hash calculation
Published 2023-10-17 · Modified
7.5EPSS 0.012
CVE-2023-38522
Apache Traffic Server: Incomplete field name check allows request smuggling
Published 2024-07-26 · Modified
7.5EPSS 0.010
CVE-2024-50305
Apache Traffic Server: Valid Host field value can cause crashes
Published 2024-11-14 · Analyzed
7.5EPSS 0.009
CVE-2024-38479
Apache Traffic Server: Cache key plugin is vulnerable to cache poisoning attack
Published 2024-11-14 · Modified
7.5EPSS 0.008
CVE-2025-49763
Apache Traffic Server: Remote DoS via memory exhaustion in ESI Plugin
Published 2025-06-19 · Analyzed
7.5EPSS 0.007
CVE-2026-59173
Apache Traffic Server: DoS vulnerability in HTTP/2 via stalled flow-control conditions
Published 2026-07-18 · Analyzed
7.5EPSS 0.007
CVE-2025-58136
Apache Traffic Server: A simple legitimate POST request causes a crash
Published 2026-04-02 · Analyzed
7.5EPSS 0.007
CVE-2024-53868
Apache Traffic Server: Malformed chunked message body allows request smuggling
Published 2025-04-03 · Analyzed
7.5EPSS 0.006
CVE-2026-58187
Apache Traffic Server: Multiplexer plugin chunk decoder enables a denial of service
Published 2026-07-29 · Analyzed
7.5EPSS 0.006
CVE-2025-31698
Apache Traffic Server: Client IP address from PROXY protocol is not used for ACL
Published 2025-06-19 · Analyzed
7.5EPSS 0.006
CVE-2025-65114
Apache Traffic Server: Malformed chunked message body allows request smuggling
Published 2026-04-02 · Analyzed
7.5EPSS 0.004
CVE-2026-24033
Apache Traffic Server: Request smuggling via chunked extension quoted-string parsing
Published 2026-07-29 · Analyzed
7.2EPSS 0.006
CVE-2026-58152
Apache Traffic Server: Integer-handling errors in HPACK/XPACK decoding corrupt memory
Published 2026-07-29 · Analyzed
6.9EPSS 0.006
CVE-2018-8004
There are multiple HTTP smuggling and cache poisoning issues when clients making malicious requests interact with Apache Traffic Server (ATS). This affects versions 6.0.0 to 6.2.2 and 7.0.0 to 7.1.3. To resolve this issue users running 6.x should upgrade to 6.2.3 or later versions and 7.x users should upgrade to 7.1.4 or later versions.
Published 2018-08-29 · Modified
6.5EPSS 0.063
CVE-2026-58160
Apache Traffic Server: Out-of-bounds reads while parsing DNS responses
Published 2026-07-29 · Analyzed
6.5EPSS 0.006
CVE-2018-9481
In bta_hd_set_report_act of bta_hd_act.cc, there is a possible out-of-bounds read due to an integer overflow. This could lead to remote information disclosure in the Bluetooth service with no additional execution privileges needed. User interaction is not needed for exploitation.
Published 2024-11-20 · Analyzed
6.5EPSS 0.001
CVE-2024-38311
Apache Traffic Server: Request smuggling via pipelining after a chunked message body
Published 2025-03-06 · Analyzed
6.3EPSS 0.009
CVE-2024-56196
Apache Traffic Server: ACL is not fully compatible with older versions
Published 2025-03-06 · Analyzed
6.3EPSS 0.008
CVE-2024-56195
Apache Traffic Server: Intercept plugins are not access controlled
Published 2025-03-06 · Analyzed
6.3EPSS 0.008
CVE-2026-65100
Apache Traffic Server: HPACK encoder desynchronizes from the decoder after a failed header encode
Published 2026-07-29 · Analyzed
6.3EPSS 0.006
CVE-2026-58156
Apache Traffic Server: URL and port parsing errors allow access-control bypass
Published 2026-07-29 · Analyzed
6.3EPSS 0.004
CVE-2026-65325
Apache Traffic Server: HTTP/2 multiplexed origin sessions are reused without certificate re-verification
Published 2026-07-29 · Analyzed
6.3EPSS 0.003
CVE-2022-40743
Apache Traffic Server: Security issues with the xdebug plugin
Published 2022-12-19 · Modified
6.1EPSS 0.011
CVE-2018-8040
Pages that are rendered using the ESI plugin can have access to the cookie header when the plugin is configured not to allow access. This affects Apache Traffic Server (ATS) versions 6.0.0 to 6.2.2 and 7.0.0 to 7.1.3. To resolve this issue users running 6.x should upgrade to 6.2.3 or later versions and 7.x users should upgrade to 7.1.4 or later versions.
Published 2018-08-29 · Modified
5.3EPSS 0.072
CVE-2018-8005
When there are multiple ranges in a range request, Apache Traffic Server (ATS) will read the entire object from cache. This can cause performance problems with large objects in cache. This affects versions 6.0.0 to 6.2.2 and 7.0.0 to 7.1.3. To resolve this issue users running 6.x users should upgrade to 6.2.3 or later versions and 7.x users should upgrade to 7.1.4 or later versions.
Published 2018-08-29 · Modified
5.3EPSS 0.069
CVE-2022-37392
Apache Traffic Server: Improperly reading the client requests
Published 2022-12-19 · Modified
5.3EPSS 0.011
CVE-2014-10022
Apache Traffic Server before 5.1.2 allows remote attackers to cause a denial of service via unspecified vectors, related to internal buffer sizing.
Published 2015-01-13 · Modified
5.0EPSS 0.056
CVE-2010-2952
Apache Traffic Server before 2.0.1, and 2.1.x before 2.1.2-unstable, does not properly choose DNS source ports and transaction IDs, and does not properly use DNS query fields to validate responses, which makes it easier for man-in-the-middle attackers to poison the internal DNS cache via a crafted response.
Published 2010-09-13 · Modified
4.3EPSS 0.026
CVE-2024-56202
Apache Traffic Server: Expect header field can unreasonably retain resource
Published 2025-03-06 · Analyzed
4.3EPSS 0.009
← Prev3 / 3