VYPR

trafficserver

by Apache

Source repositories

CVEs (121)

  • CVE-2026-58160MedJul 29, 2026
    risk 0.35cvss 6.5epss 0.01

    Apache Traffic Server reads out of bounds while parsing DNS answers. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.11, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the…

  • CVE-2018-8040MedAug 29, 2018
    risk 0.35cvss 5.3epss 0.07

    Pages that are rendered using the ESI plugin can have access to the cookie header when the plugin is configured not to allow access. This affects Apache Traffic Server (ATS) versions 6.0.0 to 6.2.2 and 7.0.0 to 7.1.3. To resolve this issue users running 6.x should upgrade to…

  • CVE-2018-8005MedAug 29, 2018
    risk 0.35cvss 5.3epss 0.07

    When there are multiple ranges in a range request, Apache Traffic Server (ATS) will read the entire object from cache. This can cause performance problems with large objects in cache. This affects versions 6.0.0 to 6.2.2 and 7.0.0 to 7.1.3. To resolve this issue users running…

  • CVE-2024-56196MedMar 6, 2025
    risk 0.34cvss 6.3epss 0.01

    Improper Access Control vulnerability in Apache Traffic Server. This issue affects Apache Traffic Server: from 10.0.0 through 10.0.3. Users are recommended to upgrade to version 10.0.4, which fixes the issue.

  • CVE-2024-56195MedMar 6, 2025
    risk 0.34cvss 6.3epss 0.01

    Improper Access Control vulnerability in Apache Traffic Server. This issue affects Apache Traffic Server: from 9.2.0 through 9.2.8, from 10.0.0 through 10.0.3. Users are recommended to upgrade to version 9.2.9 or 10.0.4, which fixes the issue.

  • CVE-2024-38311MedMar 6, 2025
    risk 0.34cvss 6.3epss 0.01

    Improper Input Validation vulnerability in Apache Traffic Server. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.11, from 9.0.0 through 9.2.8, from 10.0.0 through 10.0.3. Users are recommended to upgrade to version 9.2.9 or 10.0.4, which fixes the issue.

  • CVE-2026-58185MedJul 29, 2026
    risk 0.31cvss 5.9epss 0.01

    The Apache Traffic Server intercept plugin has a use-after-free. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.11, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.

  • CVE-2026-58183MedJul 29, 2026
    risk 0.31cvss 5.9epss 0.01

    The Apache Traffic Server prefetch plugin can crash when processing attacker-influenced input. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.11, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or…

  • CVE-2026-58158MedJul 29, 2026
    risk 0.31cvss 5.9epss 0.01

    Apache Traffic Server mishandles PROXY protocol input, truncating ports and overflowing the stack. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.11, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15…

  • CVE-2026-58152MedJul 29, 2026
    risk 0.31cvss 5.9epss 0.01

    Apache Traffic Server mishandles integers while decoding HPACK/XPACK headers, corrupting memory. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.11, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15…

  • CVE-2026-33930MedJul 29, 2026
    risk 0.31cvss 5.9epss 0.01

    Apache Traffic Server copies the client Host header into a fixed-size stack buffer without a bound during redirect handling, so an over-long Host header overflows the stack when redirect following is enabled. This issue affects Apache Traffic Server: from 8.0.0 through…

  • CVE-2022-37392MedDec 19, 2022
    risk 0.28cvss 5.3epss 0.01

    Improper Check for Unusual or Exceptional Conditions vulnerability in handling the requests to Apache Traffic Server. This issue affects Apache Traffic Server 8.0.0 to 9.1.2.

  • CVE-2026-58156MedJul 29, 2026
    risk 0.25cvss 4.9epss 0.00

    Apache Traffic Server mis-parses ports in URLs and userinfo, allowing port-based access-control bypass. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.11, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version…

  • CVE-2026-65100MedJul 29, 2026
    risk 0.24cvss 4.8epss 0.01

    Apache Traffic Server updates the HTTP/2 HPACK dynamic table before confirming the header block encoded successfully, so an encode failure leaves the encoder out of sync with the peer decoder and corrupts subsequent header blocks on the connection. This issue affects Apache…

  • CVE-2026-65325MedJul 29, 2026
    risk 0.24cvss 4.8epss 0.00

    Apache Traffic Server reuses multiplexed HTTP/2 origin connections without verifying the server certificate covers the new request hostname. This issue affects Apache Traffic Server: from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to…

  • CVE-2024-56202MedMar 6, 2025
    risk 0.21cvss 4.3epss 0.01

    Expected Behavior Violation vulnerability in Apache Traffic Server. This issue affects Apache Traffic Server: from 9.0.0 through 9.2.8, from 10.0.0 through 10.0.3. Users are recommended to upgrade to versions 9.2.9 or 10.0.4 or newer, which fixes the issue.

  • CVE-2026-58187LowJul 29, 2026
    risk 0.17cvss 3.7epss 0.01

    The Apache Traffic Server multiplexer plugin overruns its chunk-decode buffer on upstream input, enabling denial of service. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.11, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to…

  • CVE-2014-10022Jan 13, 2015
    risk 0.00cvss —epss 0.06

    Apache Traffic Server before 5.1.2 allows remote attackers to cause a denial of service via unspecified vectors, related to internal buffer sizing.

  • CVE-2014-3525Aug 22, 2014
    risk 0.00cvss —epss 0.05

    Unspecified vulnerability in Apache Traffic Server 3.x through 3.2.5, 4.x before 4.2.1.1, and 5.x before 5.0.1 has unknown impact and attack vectors, possibly related to health checks.

  • CVE-2012-0256Mar 26, 2012
    risk 0.00cvss —epss 0.03

    Apache Traffic Server 2.0.x and 3.0.x before 3.0.4 and 3.1.x before 3.1.3 does not properly allocate heap memory, which allows remote attackers to cause a denial of service (daemon crash) via a long HTTP Host header.

Page 6 of 7