VYPR
Critical severity9.8NVD Advisory· Published Mar 23, 2020· Updated Jun 17, 2026

CVE-2020-1944

CVE-2020-1944

Description

There is a vulnerability in Apache Traffic Server 6.0.0 to 6.2.3, 7.0.0 to 7.1.8, and 8.0.0 to 8.0.5 with a smuggling attack and Transfer-Encoding and Content length headers. Upgrade to versions 7.1.9 and 8.0.6 or later versions.

Affected products

4
  • Apache/Traffic Serverdescription
  • Apache/trafficserverllm-fuzzy2 versions
    6.0.0 - 6.2.3, 7.0.0 - 7.1.8, 8.0.0 - 8.0.5+ 1 more
    • (no CPE)range: 6.0.0 - 6.2.3, 7.0.0 - 7.1.8, 8.0.0 - 8.0.5
    • cpe:2.3:a:apache:traffic_server:*:*:*:*:*:*:*:*range: >=6.0.0,<=6.2.3
  • cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.