VYPR
High severity7.5NVD Advisory· Published Nov 3, 2021· Updated Jun 17, 2026

CVE-2021-37147

CVE-2021-37147

Description

Improper input validation vulnerability in header parsing of Apache Traffic Server allows an attacker to smuggle requests. This issue affects Apache Traffic Server 8.0.0 to 8.1.2 and 9.0.0 to 9.1.0.

Affected products

5
  • cpe:2.3:a:apache:traffic_server:*:*:*:*:*:*:*:*+ 2 more
    • cpe:2.3:a:apache:traffic_server:*:*:*:*:*:*:*:*range: >=8.0.0,<=8.1.2
    • (no CPE)range: 8.0.0-8.1.2, 9.0.0-9.1.0
    • (no CPE)range: 8.0.0 to 8.1.2 and 9.0.0 to 9.1.0
  • Debian/linux2 versions
    cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*
    • cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:*

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.