Critical severity9.8NVD Advisory· Published Mar 23, 2020· Updated Jun 17, 2026
CVE-2019-17565
CVE-2019-17565
Description
There is a vulnerability in Apache Traffic Server 6.0.0 to 6.2.3, 7.0.0 to 7.1.8, and 8.0.0 to 8.0.5 with a smuggling attack and chunked encoding. Upgrade to versions 7.1.9 and 8.0.6 or later versions.
Affected products
46.0.0 - 6.2.3, 7.0.0 - 7.1.8, 8.0.0 - 8.0.5+ 1 more
- (no CPE)range: 6.0.0 - 6.2.3, 7.0.0 - 7.1.8, 8.0.0 - 8.0.5
- cpe:2.3:a:apache:traffic_server:*:*:*:*:*:*:*:*range: >=6.0.0,<=6.2.3
- Apache/Traffic Serverdescription
Patches
Vulnerability mechanics
References
2- lists.apache.org/thread.html/r99d18d0bc4daa05e7d0e5a63e0e22701a421b2ef5a8f4f7694c43869%40%3Cannounce.trafficserver.apache.org%3EnvdMailing ListVendor Advisory
- www.debian.org/security/2020/dsa-4672nvdThird Party Advisory
News mentions
0No linked articles in our index yet.