VYPR

trafficserver

by Apache

Source repositories

CVEs (121)

  • CVE-2021-37149HigNov 3, 2021
    risk 0.49cvss 7.5epss 0.03

    Improper Input Validation vulnerability in header parsing of Apache Traffic Server allows an attacker to smuggle requests. This issue affects Apache Traffic Server 8.0.0 to 8.1.2 and 9.0.0 to 9.1.0.

  • CVE-2021-37148HigNov 3, 2021
    risk 0.49cvss 7.5epss 0.03

    Improper input validation vulnerability in header parsing of Apache Traffic Server allows an attacker to smuggle requests. This issue affects Apache Traffic Server 8.0.0 to 8.1.2 and 9.0.0 to 9.0.1.

  • CVE-2021-37147HigNov 3, 2021
    risk 0.49cvss 7.5epss 0.02

    Improper input validation vulnerability in header parsing of Apache Traffic Server allows an attacker to smuggle requests. This issue affects Apache Traffic Server 8.0.0 to 8.1.2 and 9.0.0 to 9.1.0.

  • CVE-2021-32567HigJun 30, 2021
    risk 0.49cvss 7.5epss 0.02

    Improper Input Validation vulnerability in HTTP/2 of Apache Traffic Server allows an attacker to DOS the server. This issue affects Apache Traffic Server 7.0.0 to 7.1.12, 8.0.0 to 8.1.1, 9.0.0 to 9.0.1.

  • CVE-2021-32566HigJun 30, 2021
    risk 0.49cvss 7.5epss 0.03

    Improper Input Validation vulnerability in HTTP/2 of Apache Traffic Server allows an attacker to DOS the server. This issue affects Apache Traffic Server 7.0.0 to 7.1.12, 8.0.0 to 8.1.1, 9.0.0 to 9.0.1.

  • CVE-2021-32565HigJun 29, 2021
    risk 0.49cvss 7.5epss 0.02

    Invalid values in the Content-Length header sent to Apache Traffic Server allows an attacker to smuggle requests. This issue affects Apache Traffic Server 7.0.0 to 7.1.12, 8.0.0 to 8.1.1, 9.0.0 to 9.0.1.

  • CVE-2021-27577HigJun 29, 2021
    risk 0.49cvss 7.5epss 0.04

    Incorrect handling of url fragment vulnerability of Apache Traffic Server allows an attacker to poison the cache. This issue affects Apache Traffic Server 7.0.0 to 7.1.12, 8.0.0 to 8.1.1, 9.0.0 to 9.0.1.

  • CVE-2021-27737HigMay 14, 2021
    risk 0.49cvss 7.5epss 0.04

    Apache Traffic Server 9.0.0 is vulnerable to a remote DOS attack on the experimental Slicer plugin.

  • CVE-2020-17509HigJan 11, 2021
    risk 0.49cvss 7.5epss 0.02

    ATS negative cache option is vulnerable to a cache poisoning attack. If you have this option enabled, please upgrade or disable this feature. Apache Traffic Server versions 7.0.0 to 7.1.11 and 8.0.0 to 8.1.0 are affected.

  • CVE-2020-17508HigJan 11, 2021
    risk 0.49cvss 7.5epss 0.02

    The ATS ESI plugin has a memory disclosure vulnerability. If you are running the plugin please upgrade. Apache Traffic Server versions 7.0.0 to 7.1.11 and 8.0.0 to 8.1.0 are affected.

  • CVE-2020-9494HigJun 24, 2020
    risk 0.49cvss 7.5epss 0.04

    Apache Traffic Server 6.0.0 to 6.2.3, 7.0.0 to 7.1.10, and 8.0.0 to 8.0.7 is vulnerable to certain types of HTTP/2 HEADERS frames that can cause the server to allocate a large amount of memory and spin the thread.

  • CVE-2020-9481HigApr 27, 2020
    risk 0.49cvss 7.5epss 0.02

    Apache ATS 6.0.0 to 6.2.3, 7.0.0 to 7.1.9, and 8.0.0 to 8.0.6 is vulnerable to a HTTP/2 slow read attack.

  • CVE-2018-11783HigMar 7, 2019
    risk 0.49cvss 7.5epss 0.02

    sslheaders plugin extracts information from the client certificate and sets headers in the request based on the configuration of the plugin. The plugin doesn't strip the headers from the request in some scenarios. This problem was discovered in versions 6.0.0 to 6.0.3, 7.0.0 to…

  • CVE-2017-7671HigFeb 27, 2018
    risk 0.49cvss 7.5epss 0.02

    There is a DOS attack vulnerability in Apache Traffic Server (ATS) 5.2.0 to 5.3.2, 6.0.0 to 6.2.0, and 7.0.0 with the TLS handshake. This issue can cause the server to coredump.

  • CVE-2017-5659HigApr 17, 2017
    risk 0.49cvss 7.5epss 0.03

    Apache Traffic Server before 6.2.1 generates a coredump when there is a mismatch between content length and chunked encoding.

  • CVE-2016-5396HigApr 17, 2017
    risk 0.49cvss 7.5epss 0.03

    Apache Traffic Server 6.0.0 to 6.2.0 are affected by an HPACK Bomb Attack.

  • CVE-2019-9514HigAug 13, 2019
    risk 0.48cvss 7.5epss 0.83

    Some HTTP/2 implementations are vulnerable to a reset flood, potentially leading to a denial of service. The attacker opens a number of streams and sends an invalid request over each stream that should solicit a stream of RST_STREAM frames from the peer. Depending on how the…

  • CVE-2019-9512HigAug 13, 2019
    risk 0.48cvss 7.5epss 0.83

    Some HTTP/2 implementations are vulnerable to ping floods, potentially leading to a denial of service. The attacker sends continual pings to an HTTP/2 peer, causing the peer to build an internal queue of responses. Depending on how efficiently this data is queued, this can…

  • CVE-2026-58153HigJul 29, 2026
    risk 0.47cvss 8.3epss 0.00

    Apache Traffic Server forwards HTTP/2 origin trailers to HTTP/1 clients without proper chunked framing when converting HTTP/2 to HTTP/1. This issue affects Apache Traffic Server: from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which…

  • CVE-2026-24033HigJul 29, 2026
    risk 0.47cvss 7.2epss 0.00

    Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') vulnerability in Apache Traffic Server. This issue affects Apache Traffic Server: from 10.0.0 through 10.1.3, from 9.0.0 through 9.2.14. Users are recommended to upgrade to version 9.2.15 or…

Page 3 of 7