Apache Traffic Server
Apache Software Foundation- Product type
- Other
- Catalog vulnerabilities
- 95
en
Severity across 95 analyzed records
Verify to analyze this security profile
As of 09/29/2026, within CyStack's analyzed data, Apache Traffic Server has 39 security vulnerabilities published in the last 90 days. Of these, 29 are rated High or Critical. None of these vulnerabilities is listed in the CISA KEV catalog. CyStack recommends that organizations and individual users remediate applicable vulnerabilities as soon as possible.
CyStack does not yet have sufficient official-source data to identify the latest version of Apache Traffic Server and determine which vulnerabilities affect that version.
| Vulnerability | Exploitation status | Fix | Published | Severity |
|---|---|---|---|---|
CVE-2026-65100Apache Traffic Server: HPACK encoder desynchronizes from the decoder after a failed header encode | Exploitation statusNot known exploited | FixYes | Published07/29/2026 | SeverityMedium |
CVE-2026-58189Apache Traffic Server: Plugins resetting the redirect counter enable SSRF amplification | Exploitation statusNot known exploited | FixYes | Published07/29/2026 | SeverityHigh |
CVE-2026-58188Apache Traffic Server: Memory-safety and limit-bypass errors across experimental plugins | Exploitation statusNot known exploited | FixYes | Published07/29/2026 | SeverityHigh |
CVE-2026-58187Apache Traffic Server: Multiplexer plugin chunk decoder enables a denial of service | Exploitation statusNot known exploited | FixYes | Published07/29/2026 | SeverityMedium |
CVE-2026-58186Apache Traffic Server: webp_transform plugin decodes unsafely and mislabels degraded responses | Exploitation statusNot known exploited | FixYes | Published07/29/2026 | SeverityHigh |
CVE-2026-58185Apache Traffic Server: Use-after-free in the intercept plugin | Exploitation statusNot known exploited | FixYes | Published07/29/2026 | SeverityHigh |
CVE-2026-58184Apache Traffic Server: header_rewrite plugin cookie handling can corrupt memory | Exploitation statusNot known exploited | FixYes | Published07/29/2026 | SeverityHigh |
CVE-2026-58183Apache Traffic Server: prefetch plugin can crash on attacker-influenced input | Exploitation statusNot known exploited | FixYes | Published07/29/2026 | SeverityHigh |
CVE-2026-58182Apache Traffic Server: ts_lua plugin has initialization and resource-handling errors | Exploitation statusNot known exploited | FixYes | Published07/29/2026 | SeverityHigh |
CVE-2026-58181Apache Traffic Server: uri_signing and url_sig plugins can exhaust the stack or crash | Exploitation statusNot known exploited | FixYes | Published07/29/2026 | SeverityHigh |
CVE-2026-58180Apache Traffic Server: txn_box plugin overflows the stack from attacker input | Exploitation statusNot known exploited | FixYes | Published07/29/2026 | SeverityHigh |
CVE-2026-58179Apache Traffic Server: regex_remap plugin overflows the stack from attacker input | Exploitation statusNot known exploited | FixYes | Published07/29/2026 | SeverityCritical |
CVE-2026-58178Apache Traffic Server: ESI plugin allows uncontrolled recursion and server-side request forgery | Exploitation statusNot known exploited | FixYes | Published07/29/2026 | SeverityHigh |
CVE-2026-58177Apache Traffic Server: Memory-safety and path-traversal errors in the Cripts framework | Exploitation statusNot known exploited | FixYes | Published07/29/2026 | SeverityHigh |
CVE-2026-58175Apache Traffic Server: HostDB SRV handling leaks memory | Exploitation statusNot known exploited | FixYes | Published07/29/2026 | SeverityHigh |
CVE-2026-58164Apache Traffic Server: Remap configuration lifetime and TOCTOU errors cause use-after-free | Exploitation statusNot known exploited | FixYes | Published07/29/2026 | SeverityHigh |
CVE-2026-58163Apache Traffic Server: Cache deserialization and lifetime errors can corrupt state or crash the server | Exploitation statusNot known exploited | FixYes | Published07/29/2026 | SeverityHigh |
CVE-2026-58162Apache Traffic Server: Certifier plugin trusts client SNI when generating certificates | Exploitation statusNot known exploited | FixYes | Published07/29/2026 | SeverityHigh |
CVE-2026-58161Apache Traffic Server: Memory-safety errors in TLS and SNI handling can crash the server | Exploitation statusNot known exploited | FixYes | Published07/29/2026 | SeverityCritical |
CVE-2026-58160Apache Traffic Server: Out-of-bounds reads while parsing DNS responses | Exploitation statusNot known exploited | FixYes | Published07/29/2026 | SeverityMedium |
CVE-2026-58159Apache Traffic Server: Listener and ACL handling allow access-control bypass | Exploitation statusNot known exploited | FixYes | Published07/29/2026 | SeverityHigh |
CVE-2026-58158Apache Traffic Server: PROXY protocol parsing has port truncation and a stack overflow | Exploitation statusNot known exploited | FixYes | Published07/29/2026 | SeverityHigh |
CVE-2026-58157Apache Traffic Server: Improper server-session reuse can expose data across client connections | Exploitation statusNot known exploited | FixYes | Published07/29/2026 | SeverityMedium |
CVE-2026-58156Apache Traffic Server: URL and port parsing errors allow access-control bypass | Exploitation statusNot known exploited | FixYes | Published07/29/2026 | SeverityMedium |
CVE-2026-58155Apache Traffic Server: Header-name length truncation enables header aliasing and request smuggling | Exploitation statusNot known exploited | FixYes | Published07/29/2026 | SeverityCritical |
CVE-2026-58154Apache Traffic Server: Memory-safety errors in MIME and header parsing | Exploitation statusNot known exploited | FixYes | Published07/29/2026 | SeverityCritical |
CVE-2026-65325Apache Traffic Server: HTTP/2 multiplexed origin sessions are reused without certificate re-verification | Exploitation statusNot known exploited | FixYes | Published07/29/2026 | SeverityMedium |
CVE-2026-65324Apache Traffic Server: HTTP/2 and HTTP/3 dechunking removes per-stream buffer cap, allowing memory exhaustion | Exploitation statusNot known exploited | FixYes | Published07/29/2026 | SeverityHigh |
CVE-2026-58153Apache Traffic Server: HTTP/2 to HTTP/1 conversion forwards origin trailers to clients unsafely | Exploitation statusNot known exploited | FixYes | Published07/29/2026 | SeverityMedium |
CVE-2026-58152Apache Traffic Server: Integer-handling errors in HPACK/XPACK decoding corrupt memory | Exploitation statusNot known exploited | FixYes | Published07/29/2026 | SeverityMedium |
CVE-2026-58151Apache Traffic Server: Abusive HTTP/2 framing can exhaust resources and crash the server | Exploitation statusNot known exploited | FixYes | Published07/29/2026 | SeverityHigh |
CVE-2026-58150Apache Traffic Server: HTTP/2 requests with Transfer-Encoding are not rejected, allowing request smuggling | Exploitation statusNot known exploited | FixYes | Published07/29/2026 | SeverityHigh |
CVE-2026-57834Apache Traffic Server: Malformed chunked message body allows request smuggling | Exploitation statusNot known exploited | FixYes | Published07/29/2026 | SeverityHigh |
CVE-2026-33930Apache Traffic Server: Buffer overflow via Host field that has a long string value | Exploitation statusNot known exploited | FixYes | Published07/29/2026 | SeverityHigh |
CVE-2026-24033Apache Traffic Server: Request smuggling via chunked extension quoted-string parsing | Exploitation statusNot known exploited | FixYes | Published07/29/2026 | SeverityMedium |
CVE-2026-33267Apache Traffic Server: Untrusted @ headers can spoof ATS internal metadata | Exploitation statusNot known exploited | FixYes | Published07/29/2026 | SeverityHigh |
CVE-2026-22068Apache Traffic Server: Regex mappings match with malicious domain names | Exploitation statusNot known exploited | FixYes | Published07/29/2026 | SeverityMedium |
CVE-2026-41920Apache Traffic Server: SNI to Host header matching policy is not properly enforced | Exploitation statusNot known exploited | FixYes | Published07/29/2026 | SeverityHigh |
CVE-2026-59173Apache Traffic Server: DoS vulnerability in HTTP/2 via stalled flow-control conditions | Exploitation statusNot known exploited | FixYes | Published07/18/2026 | SeverityHigh |
CVE-2025-65114Apache Traffic Server: Malformed chunked message body allows request smuggling | Exploitation statusNot known exploited | FixYes | Published04/02/2026 | SeverityHigh |
CVE-2025-58136Apache Traffic Server: A simple legitimate POST request causes a crash | Exploitation statusNot known exploited | FixYes | Published04/02/2026 | SeverityHigh |
CVE-2025-31698Apache Traffic Server: Client IP address from PROXY protocol is not used for ACL | Exploitation statusNot known exploited | FixYes | Published06/19/2025 | SeverityHigh |
CVE-2025-49763Apache Traffic Server: Remote DoS via memory exhaustion in ESI Plugin | Exploitation statusNot known exploited | FixYes | Published06/19/2025 | SeverityHigh |
CVE-2024-53868Apache Traffic Server: Malformed chunked message body allows request smuggling | Exploitation statusNot known exploited | FixYes | Published04/03/2025 | SeverityHigh |
CVE-2024-38311Apache Traffic Server: Request smuggling via pipelining after a chunked message body | Exploitation statusNot known exploited | FixYes | Published03/06/2025 | SeverityMedium |
CVE-2024-56195Apache Traffic Server: Intercept plugins are not access controlled | Exploitation statusNot known exploited | FixYes | Published03/06/2025 | SeverityMedium |
CVE-2024-56196Apache Traffic Server: ACL is not fully compatible with older versions | Exploitation statusNot known exploited | FixYes | Published03/06/2025 | SeverityMedium |
CVE-2024-56202Apache Traffic Server: Expect header field can unreasonably retain resource | Exploitation statusNot known exploited | FixYes | Published03/06/2025 | SeverityMedium |
CVE-2024-50306Apache Traffic Server: Server process can fail to drop privilege | Exploitation statusNot known exploited | FixYes | Published11/14/2024 | SeverityCritical |
CVE-2024-50305Apache Traffic Server: Valid Host field value can cause crashes | Exploitation statusNot known exploited | FixYes | Published11/14/2024 | SeverityHigh |
CVE-2024-38479Apache Traffic Server: Cache key plugin is vulnerable to cache poisoning attack | Exploitation statusNot known exploited | FixYes | Published11/14/2024 | SeverityHigh |
CVE-2023-38522Apache Traffic Server: Incomplete field name check allows request smuggling | Exploitation statusNot known exploited | FixYes | Published07/26/2024 | SeverityHigh |
CVE-2024-35296Apache Traffic Server: Invalid Accept-Encoding can force forwarding requests | Exploitation statusNot known exploited | FixYes | Published07/26/2024 | SeverityHigh |
CVE-2024-35161Apache Traffic Server: Incomplete check for chunked trailer section allows request smuggling | Exploitation statusNot known exploited | FixYes | Published07/26/2024 | SeverityCritical |
CVE-2024-31309Apache Traffic Server: HTTP/2 CONTINUATION frames can be utilized for DoS attack | Exploitation statusNot known exploited | FixYes | Published04/10/2024 | SeverityHigh |
CVE-2023-39456Apache Traffic Server: Malformed http/2 frames can cause an abort | Exploitation statusNot known exploited | FixYes | Published10/17/2023 | SeverityHigh |
CVE-2023-41752Apache Traffic Server: s3_auth plugin problem with hash calculation | Exploitation statusNot known exploited | FixYes | Published10/17/2023 | SeverityHigh |
CVE-2023-33934Apache Traffic Server: Differential fuzzing for HTTP request parsing discrepancies | Exploitation statusNot known exploited | FixYes | Published08/09/2023 | SeverityCritical |
CVE-2022-47185Apache Traffic Server: Invalid Range header causes a crash | Exploitation statusNot known exploited | FixYes | Published08/09/2023 | SeverityHigh |
CVE-2023-30631Apache Traffic Server: Configuration option to block the PUSH method in ATS didn't work | Exploitation statusNot confirmed | FixYes | Published06/14/2023 | SeverityUnknown |
CVE-2023-33933Apache Traffic Server: s3_auth plugin problem with hash calculation | Exploitation statusNot known exploited | FixYes | Published06/14/2023 | SeverityHigh |
CVE-2022-47184Apache Traffic Server: The TRACE method can be use to disclose network information | Exploitation statusNot known exploited | FixYes | Published06/14/2023 | SeverityHigh |
CVE-2022-40743Apache Traffic Server: Security issues with the xdebug plugin | Exploitation statusNot known exploited | FixYes | Published12/19/2022 | SeverityMedium |
CVE-2022-37392Apache Traffic Server: Improperly reading the client requests | Exploitation statusNot known exploited | FixYes | Published12/19/2022 | SeverityMedium |
CVE-2022-32749Apache Traffic Server: Improperly handled requests can cause crashes in specific plugins | Exploitation statusNot known exploited | FixYes | Published12/19/2022 | SeverityHigh |
CVE-2022-31779Improper HTTP/2 scheme and method validation | Exploitation statusNot confirmed | FixNot confirmed | Published08/10/2022 | SeverityUnknown |
CVE-2022-25763Improper input validation on HTTP/2 headers | Exploitation statusNot known exploited | FixNot confirmed | Published08/10/2022 | SeverityMedium |
CVE-2022-28129Insufficient Validation of HTTP/1.x Headers | Exploitation statusNot confirmed | FixNot confirmed | Published08/10/2022 | SeverityUnknown |
CVE-2022-31778Transfer-Encoding not treated as hop-by-hop | Exploitation statusNot confirmed | FixNot confirmed | Published08/10/2022 | SeverityUnknown |
CVE-2022-31780HTTP/2 framing vulnerabilities | Exploitation statusNot confirmed | FixNot confirmed | Published08/10/2022 | SeverityUnknown |
CVE-2021-37150Protocol vs scheme mismatch | Exploitation statusNot known exploited | FixNot confirmed | Published08/10/2022 | SeverityMedium |
CVE-2021-44759Improper authentication vulnerability in TLS origin verification | Exploitation statusNot confirmed | FixNot confirmed | Published03/23/2022 | SeverityUnknown |
CVE-2021-44040HTTP request line fuzzing attacks | Exploitation statusNot confirmed | FixNot confirmed | Published03/23/2022 | SeverityUnknown |
CVE-2021-43082heap-buffer-overflow with stats-over-http plugin | Exploitation statusNot confirmed | FixNot confirmed | Published11/03/2021 | SeverityUnknown |
CVE-2021-41585ATS stops accepting connections on FreeBSD | Exploitation statusNot confirmed | FixNot confirmed | Published11/03/2021 | SeverityUnknown |
CVE-2021-38161Not validating origin TLS certificate | Exploitation statusNot confirmed | FixNot confirmed | Published11/03/2021 | SeverityUnknown |
CVE-2021-37149Request Smuggling - multiple attacks | Exploitation statusNot confirmed | FixNot confirmed | Published11/03/2021 | SeverityUnknown |
CVE-2021-37148Request Smuggling - transfer encoding validation | Exploitation statusNot confirmed | FixNot confirmed | Published11/03/2021 | SeverityUnknown |
CVE-2021-37147Request Smuggling - LF line ending | Exploitation statusNot confirmed | FixNot confirmed | Published11/03/2021 | SeverityUnknown |
CVE-2021-35474Dynamic stack buffer overflow in cachekey plugin | Exploitation statusNot confirmed | FixNot confirmed | Published06/30/2021 | SeverityUnknown |
CVE-2021-32567Reading HTTP/2 frames too many times | Exploitation statusNot confirmed | FixNot confirmed | Published06/30/2021 | SeverityUnknown |
CVE-2021-32566Specific sequence of HTTP/2 frames can cause ATS to crash | Exploitation statusNot confirmed | FixNot confirmed | Published06/30/2021 | SeverityUnknown |
CVE-2021-32565HTTP Request Smuggling, content length with invalid charters | Exploitation statusNot confirmed | FixNot confirmed | Published06/29/2021 | SeverityUnknown |
CVE-2021-27577Incorrect handling of url fragment leads to cache poisoning | Exploitation statusNot confirmed | FixNot confirmed | Published06/29/2021 | SeverityUnknown |
CVE-2020-9494 | Exploitation statusNot confirmed | FixNot confirmed | Published06/24/2020 | SeverityUnknown |
CVE-2018-11783 | Exploitation statusNot confirmed | FixNot confirmed | Published03/07/2019 | SeverityUnknown |
CVE-2018-8022 | Exploitation statusNot confirmed | FixNot confirmed | Published08/29/2018 | SeverityUnknown |
CVE-2018-8040 | Exploitation statusNot confirmed | FixNot confirmed | Published08/29/2018 | SeverityUnknown |
CVE-2018-8004 | Exploitation statusNot confirmed | FixNot confirmed | Published08/29/2018 | SeverityUnknown |
CVE-2018-8005 | Exploitation statusNot confirmed | FixNot confirmed | Published08/29/2018 | SeverityUnknown |
CVE-2018-1318 | Exploitation statusNot confirmed | FixNot confirmed | Published08/29/2018 | SeverityUnknown |
CVE-2017-5660 | Exploitation statusNot confirmed | FixNot confirmed | Published02/27/2018 | SeverityUnknown |
CVE-2017-7671 | Exploitation statusNot confirmed | FixNot confirmed | Published02/27/2018 | SeverityUnknown |
CVE-2017-5659 | Exploitation statusNot confirmed | FixNot confirmed | Published04/17/2017 | SeverityUnknown |
CVE-2016-5396 | Exploitation statusNot confirmed | FixNot confirmed | Published04/17/2017 | SeverityUnknown |
CyStack VulnScan continuously discovers assets, validates vulnerabilities, and helps security teams prioritize remediation across the organization.
Explore CyStack VulnScan