High severity8.2NVD Advisory· Published Jul 26, 2024· Updated Jun 17, 2026
CVE-2024-35296
CVE-2024-35296
Description
Invalid Accept-Encoding header can cause Apache Traffic Server to fail cache lookup and force forwarding requests.
This issue affects Apache Traffic Server: from 8.0.0 through 8.1.10, from 9.0.0 through 9.2.4.
Users are recommended to upgrade to version 8.1.11 or 9.2.5, which fixes the issue.
Affected products
3from 8.0.0 through 8.1.10, from 9.0.0 through 9.2.4+ 2 more
- (no CPE)range: from 8.0.0 through 8.1.10, from 9.0.0 through 9.2.4
- (no CPE)range: 8.0.0
- cpe:2.3:a:apache:traffic_server:*:*:*:*:*:*:*:*range: >=8.0.0,<8.1.11
Patches
Vulnerability mechanics
References
2- lists.apache.org/thread/c4mcmpblgl8kkmyt56t23543gp8v56m0nvdMailing ListVendor Advisory
- lists.debian.org/debian-lts-announce/2024/09/msg00040.htmlnvd
News mentions
0No linked articles in our index yet.