High severity7.5NVD Advisory· Published Nov 3, 2021· Updated Jun 17, 2026
CVE-2021-37147
CVE-2021-37147
Description
Improper input validation vulnerability in header parsing of Apache Traffic Server allows an attacker to smuggle requests. This issue affects Apache Traffic Server 8.0.0 to 8.1.2 and 9.0.0 to 9.1.0.
Affected products
5cpe:2.3:a:apache:traffic_server:*:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:apache:traffic_server:*:*:*:*:*:*:*:*range: >=8.0.0,<=8.1.2
- (no CPE)range: 8.0.0-8.1.2, 9.0.0-9.1.0
- (no CPE)range: 8.0.0 to 8.1.2 and 9.0.0 to 9.1.0
Patches
Vulnerability mechanics
References
2- lists.apache.org/thread/k01797hyncx53659wr3o72s5cvkc3164nvdMailing ListPatchVendor Advisory
- www.debian.org/security/2022/dsa-5153nvdThird Party Advisory
News mentions
0No linked articles in our index yet.