High severity7.5NVD Advisory· Published Nov 14, 2024· Updated Jun 17, 2026
CVE-2024-38479
CVE-2024-38479
Description
Improper Input Validation vulnerability in Apache Traffic Server.
This issue affects Apache Traffic Server: from 8.0.0 through 8.1.11, from 9.0.0 through 9.2.5.
Users are recommended to upgrade to version 9.2.6, which fixes the issue, or 10.0.2, which does not have the issue.
Affected products
4from 8.0.0 through 8.1.11, from 9.0.0 through 9.2.5+ 3 more
- (no CPE)range: from 8.0.0 through 8.1.11, from 9.0.0 through 9.2.5
- (no CPE)range: 8.0.0
- cpe:2.3:a:apache:traffic_server:*:*:*:*:*:*:*:*range: >=8.0.0,<=8.1.11
- cpe:2.3:a:apache:traffic_server:*:-:*:*:*:*:*:*range: >=9.0.0,<9.2.6
Patches
Vulnerability mechanics
References
2- lists.apache.org/thread/y15fh6c7kyqvzm0f9odw7c5jh4r4np0ynvdMailing ListVendor Advisory
- lists.debian.org/debian-lts-announce/2025/02/msg00018.htmlnvd
News mentions
0No linked articles in our index yet.