High severity8.2NVD Advisory· Published Jul 26, 2024· Updated Jun 17, 2026
CVE-2024-35296
CVE-2024-35296
Description
Invalid Accept-Encoding header can cause Apache Traffic Server to fail cache lookup and force forwarding requests.
This issue affects Apache Traffic Server: from 8.0.0 through 8.1.10, from 9.0.0 through 9.2.4.
Users are recommended to upgrade to version 8.1.11 or 9.2.5, which fixes the issue.
Affected products
3cpe:2.3:a:apache:traffic_server:*:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:apache:traffic_server:*:*:*:*:*:*:*:*range: >=8.0.0,<8.1.11
- (no CPE)range: from 8.0.0 through 8.1.10, from 9.0.0 through 9.2.4
- (no CPE)range: 8.0.0
Patches
Vulnerability mechanics
References
2- lists.apache.org/thread/c4mcmpblgl8kkmyt56t23543gp8v56m0nvdMailing ListVendor Advisory
- lists.debian.org/debian-lts-announce/2024/09/msg00040.htmlnvd
News mentions
0No linked articles in our index yet.