📦 Traffic Server

by Apache

🔍 What is Traffic Server?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2024-50306

CRITICAL CVSS 9.1 Nov 14, 2024

Apache Traffic Server fails to properly handle return values during startup, potentially allowing the service to retain elevated privileges it should drop. This affects all users running Apache Traffi...

CVE-2023-33934

CRITICAL CVSS 9.1 Aug 9, 2023

CVE-2023-33934 is an improper input validation vulnerability in Apache Traffic Server that could allow remote attackers to execute arbitrary code or cause denial of service. This affects all Apache Tr...

CVE-2021-43082

CRITICAL CVSS 9.8 Nov 3, 2021

This CVE describes a classic buffer overflow vulnerability in Apache Traffic Server's stats-over-http plugin that allows attackers to overwrite memory. Attackers could potentially execute arbitrary co...

CVE-2021-35474

CRITICAL CVSS 9.8 Jun 30, 2021

A stack-based buffer overflow vulnerability in Apache Traffic Server's cachekey plugin allows remote attackers to execute arbitrary code or cause denial of service. This affects Apache Traffic Server ...

CVE-2025-31698

HIGH CVSS 7.5 Jun 19, 2025

Apache Traffic Server versions 9.0.0-9.2.10 and 10.0.0-10.0.6 have an ACL bypass vulnerability when using PROXY protocol. The access control lists in ip_allow.config or remap.config fail to properly u...

CVE-2024-53868

HIGH CVSS 7.5 Apr 3, 2025

Apache Traffic Server is vulnerable to HTTP request smuggling when processing malformed chunked messages. This allows attackers to bypass security controls, poison caches, or hijack user sessions. Aff...

CVE-2024-50305

HIGH CVSS 7.5 Nov 14, 2024

A vulnerability in Apache Traffic Server allows a specially crafted Host header to cause a denial-of-service crash. This affects Apache Traffic Server versions 9.2.0 through 9.2.5 on some platforms, p...

CVE-2024-38479

HIGH CVSS 7.5 Nov 14, 2024

Apache Traffic Server has an improper input validation vulnerability (CWE-20) that could allow attackers to cause denial of service or potentially execute arbitrary code by sending specially crafted r...

CVE-2024-35296

HIGH CVSS 8.2 Jul 26, 2024

Apache Traffic Server versions 8.0.0-8.1.10 and 9.0.0-9.2.4 have a vulnerability where specially crafted Accept-Encoding headers can bypass cache lookups, forcing requests to be forwarded to origin se...

CVE-2023-38522

HIGH CVSS 7.5 Jul 26, 2024

Apache Traffic Server improperly validates HTTP field names, allowing characters that violate HTTP specifications. This enables attackers to craft malformed requests that can lead to HTTP request smug...

CVE-2023-41752

HIGH CVSS 7.5 Oct 17, 2023

Apache Traffic Server versions 8.0.0-8.1.8 and 9.0.0-9.2.2 expose sensitive information to unauthorized actors. This CWE-200 vulnerability allows attackers to access confidential data they shouldn't h...

CVE-2023-44487

HIGH CVSS 7.5 Oct 10, 2023

CVE-2023-44487 is an HTTP/2 protocol vulnerability that allows attackers to cause denial of service by rapidly resetting streams, consuming server resources. This affects any system using HTTP/2, incl...

CVE-2022-47185

HIGH CVSS 7.5 Aug 9, 2023

This vulnerability allows attackers to exploit improper input validation in Apache Traffic Server's range header handling. Attackers could cause denial of service or potentially execute arbitrary code...

CVE-2023-33933

HIGH CVSS 7.5 Jun 14, 2023

Apache Traffic Server versions 8.0.0 through 9.2.0 contain an information disclosure vulnerability that allows unauthorized actors to access sensitive information. This affects all users running vulne...

CVE-2022-47184

HIGH CVSS 7.5 Jun 14, 2023

Apache Traffic Server versions 8.0.0 through 9.2.0 contain an information disclosure vulnerability that allows unauthorized actors to access sensitive information. This affects all deployments running...

CVE-2021-44040

HIGH CVSS 7.5 Mar 23, 2022

CVE-2021-44040 is an improper input validation vulnerability in Apache Traffic Server's request line parsing that allows attackers to send invalid requests, potentially causing denial of service or ot...

CVE-2021-37149

HIGH CVSS 7.5 Nov 3, 2021

This CVE describes an improper input validation vulnerability in Apache Traffic Server's header parsing that allows attackers to smuggle HTTP requests. Attackers can bypass security controls and poten...

CVE-2021-41585

HIGH CVSS 7.5 Nov 3, 2021

An improper input validation vulnerability in Apache Traffic Server's socket connection handling allows attackers to send malicious requests that cause the server to stop accepting new connections. Th...

CVE-2021-37147

HIGH CVSS 7.5 Nov 3, 2021

CVE-2021-37147 is an improper input validation vulnerability in Apache Traffic Server's header parsing that allows HTTP request smuggling. Attackers can exploit this to bypass security controls, poiso...

CVE-2021-32566

HIGH CVSS 7.5 Jun 30, 2021

CVE-2021-32566 is an improper input validation vulnerability in Apache Traffic Server's HTTP/2 implementation that allows attackers to cause a denial-of-service (DoS) condition. The vulnerability affe...

CVE-2021-27577

HIGH CVSS 7.5 Jun 29, 2021

Apache Traffic Server incorrectly handles URL fragments, allowing attackers to poison the cache by manipulating fragment identifiers. This affects Apache Traffic Server versions 7.0.0 to 7.1.12, 8.0.0...

CVE-2024-56196

MEDIUM CVSS 6.3 Mar 6, 2025

Apache Traffic Server versions 10.0.0 through 10.0.3 contain an improper access control vulnerability (CWE-284) that could allow unauthorized access to restricted resources. This affects all users run...

CVE-2024-38311

MEDIUM CVSS 6.3 Mar 6, 2025

Apache Traffic Server has an improper input validation vulnerability that could allow attackers to cause denial of service or potentially execute arbitrary code by sending specially crafted requests. ...