Traffic Server Apache Traffic Server

Don't miss out!

Thousands of developers use stack.watch to stay informed.
Get an email whenever new security vulnerabilities are reported in Apache Traffic Server.

By the Year

In 2025 there have been 7 vulnerabilities in Apache Traffic Server. Last year, in 2024 Traffic Server had 8 security vulnerabilities published. Right now, Traffic Server is on track to have less security vulnerabilities in 2025 than it did last year.




Year Vulnerabilities Average Score
2025 7 0.00
2024 8 7.91
2023 8 7.70
2022 11 7.16
2021 14 7.87
2020 5 8.88
2019 10 7.40
2018 5 6.42

It may take a day or so for new Traffic Server vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.

Recent Apache Traffic Server Security Vulnerabilities

Apache Traffic Server ACL ignores PROXY IP – CVE-2025-31698
CVE-2025-31698 - June 19, 2025

ACL configured in ip_allow.config or remap.config does not use IP addresses that are provided by PROXY protocol. Users can use a new setting (proxy.config.acl.subjects) to choose which IP addresses to use for the ACL if Apache Traffic Server is configured to accept PROXY protocol.  This issue affects undefined: from 10.0.0 through 10.0.6, from 9.0.0 through 9.2.10. Users are recommended to upgrade to version 9.2.11 or 10.0.6, which fixes the issue.

Authorization

Apache Traffic Server ESI Plugin Depth Oops: Memory Overload (v10)
CVE-2025-49763 - June 19, 2025

ESI plugin does not have the limit for maximum inclusion depth, and that allows excessive memory consumption if malicious instructions are inserted. Users can use a new setting for the plugin (--max-inclusion-depth) to limit it. This issue affects Apache Traffic Server: from 10.0.0 through 10.0.5, from 9.0.0 through 9.2.10. Users are recommended to upgrade to version 9.2.11 or 10.0.6, which fixes the issue.

Resource Exhaustion

Apache Traffic Server 9.2.x/10.x request smuggling via malformed chunks
CVE-2024-53868 - April 03, 2025

Apache Traffic Server allows request smuggling if chunked messages are malformed.  This issue affects Apache Traffic Server: from 9.2.0 through 9.2.9, from 10.0.0 through 10.0.4. Users are recommended to upgrade to version 9.2.10 or 10.0.5, which fixes the issue.

HTTP Request Smuggling

Apache Traffic Server 10.0.0-10.0.3 IAC Vulnerability
CVE-2024-56196 - March 06, 2025

Improper Access Control vulnerability in Apache Traffic Server. This issue affects Apache Traffic Server: from 10.0.0 through 10.0.3. Users are recommended to upgrade to version 10.0.4, which fixes the issue.

Authorization

Apache Traffic Server Improper Input Validation in 8-10.x Versions
CVE-2024-38311 - March 06, 2025

Improper Input Validation vulnerability in Apache Traffic Server. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.11, from 9.0.0 through 9.2.8, from 10.0.0 through 10.0.3. Users are recommended to upgrade to version 9.2.9 or 10.0.4, which fixes the issue.

Improper Input Validation

Apache Traffic Server <=10.0.3 Improper Access Control
CVE-2024-56195 - March 06, 2025

Improper Access Control vulnerability in Apache Traffic Server. This issue affects Apache Traffic Server: from 9.2.0 through 9.2.8, from 10.0.0 through 10.0.3. Users are recommended to upgrade to version 9.2.9 or 10.0.4, which fixes the issue.

Authorization

Apache Traffic Server EBV Vulnerability (9.0.0-9.2.8 & 10.0.0-10.0.3)
CVE-2024-56202 - March 06, 2025

Expected Behavior Violation vulnerability in Apache Traffic Server. This issue affects Apache Traffic Server: from 9.0.0 through 9.2.8, from 10.0.0 through 10.0.3. Users are recommended to upgrade to versions 9.2.9 or 10.0.4 or newer, which fixes the issue.

Expected Behavior Violation

Bluetooth Service Integer Overflow Vulnerability in Android
CVE-2018-9481 6.5 - Medium - November 20, 2024

In bta_hd_set_report_act of bta_hd_act.cc, there is a possible out-of-bounds read due to an integer overflow. This could lead to remote information disclosure in the Bluetooth service with no additional execution privileges needed. User interaction is not needed for exploitation.

Integer Overflow or Wraparound

Apache Traffic Server 8.0.0-9.2.5: Improper Input Validation Vulnerability
CVE-2024-38479 7.5 - High - November 14, 2024

Improper Input Validation vulnerability in Apache Traffic Server. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.11, from 9.0.0 through 9.2.5. Users are recommended to upgrade to version 9.2.6, which fixes the issue, or 10.0.2, which does not have the issue.

Improper Input Validation

Apache Traffic Server: HTTP Header Parsing Vulnerability
CVE-2024-50305 - November 14, 2024

Valid Host header field can cause Apache Traffic Server to crash on some platforms. This issue affects Apache Traffic Server: from 9.2.0 through 9.2.5. Users are recommended to upgrade to version 9.2.6, which fixes the issue, or 10.0.2, which does not have the issue.

Improper Input Validation

Apache Traffic Server Privilege Retention Vulnerability on Startup
CVE-2024-50306 9.1 - Critical - November 14, 2024

Unchecked return value can allow Apache Traffic Server to retain privileges on startup. This issue affects Apache Traffic Server: from 9.2.0 through 9.2.5, from 10.0.0 through 10.0.1. Users are recommended to upgrade to version 9.2.6 or 10.0.2, which fixes the issue.

Unchecked Return Value

Apache Traffic Server 8.0.09.2.4: HTTP Field Name Smuggling Vulnerability
CVE-2023-38522 7.5 - High - July 26, 2024

Apache Traffic Server accepts characters that are not allowed for HTTP field names and forwards malformed requests to origin servers. This can be utilized for request smuggling and may also lead cache poisoning if the origin servers are vulnerable. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.10, from 9.0.0 through 9.2.4. Users are recommended to upgrade to version 8.1.11 or 9.2.5, which fixes the issue.

HTTP Request Smuggling

CVE-2024-35161: Traffic Server 8.0-9.2 HTTP Chunked Trailer Smuggling
CVE-2024-35161 9.1 - Critical - July 26, 2024

Apache Traffic Server forwards malformed HTTP chunked trailer section to origin servers. This can be utilized for request smuggling and may also lead cache poisoning if the origin servers are vulnerable. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.10, from 9.0.0 through 9.2.4. Users can set a new setting (proxy.config.http.drop_chunked_trailers) not to forward chunked trailer section. Users are recommended to upgrade to version 8.1.11 or 9.2.5, which fixes the issue.

HTTP Request Smuggling

Apache Traffic Server <8.1.11/9.2.5 CVE-2024-35296 Accept-Encoding Cache Flush
CVE-2024-35296 8.2 - High - July 26, 2024

Invalid Accept-Encoding header can cause Apache Traffic Server to fail cache lookup and force forwarding requests. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.10, from 9.0.0 through 9.2.4. Users are recommended to upgrade to version 8.1.11 or 9.2.5, which fixes the issue.

Improper Input Validation

Apache Traffic Server 8.0-9.2 DoS via HTTP/2 CONTINUATION (CVE-2024-31309)
CVE-2024-31309 7.5 - High - April 10, 2024

HTTP/2 CONTINUATION DoS attack can cause Apache Traffic Server to consume more resources on the server.  Version from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.3 are affected. Users can set a new setting (proxy.config.http2.max_continuation_frames_per_minute) to limit the number of CONTINUATION frames per minute.  ATS does have a fixed amount of memory a request can use and ATS adheres to these limits in previous releases. Users are recommended to upgrade to versions 8.1.10 or 9.2.4 which fixes the issue.

Improper Input Validation

Apache Traffic Server 8.x/9.x Sensitive Info Leak (v < 8.1.9/9.2.3)
CVE-2023-41752 7.5 - High - October 17, 2023

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Traffic Server.This issue affects Apache Traffic Server: from 8.0.0 through 8.1.8, from 9.0.0 through 9.2.2. Users are recommended to upgrade to version 8.1.9 or 9.2.3, which fixes the issue.

Information Disclosure

Apache TS HTTP/2 Frame Validation Flaw 9.0.0-9.2.2 (Fixed 9.2.3)
CVE-2023-39456 7.5 - High - October 17, 2023

Improper Input Validation vulnerability in Apache Traffic Server with malformed HTTP/2 frames.This issue affects Apache Traffic Server: from 9.0.0 through 9.2.2. Users are recommended to upgrade to version 9.2.3, which fixes the issue.

Improper Input Validation

HTTP/2 DoS via Stream Reset in nginx
CVE-2023-44487 7.5 - High - October 10, 2023

The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.

Resource Exhaustion

Improper Input Validation vulnerability in Apache Software Foundation Apache Traffic Server.This issue affects Apache Traffic Server: through 9.2.1.
CVE-2023-33934 9.1 - Critical - August 09, 2023

Improper Input Validation vulnerability in Apache Software Foundation Apache Traffic Server.This issue affects Apache Traffic Server: through 9.2.1.

HTTP Request Smuggling

Improper input validation vulnerability on the range header in Apache Software Foundation Apache Traffic Server.This issue affects Apache Traffic Server: through 9.2.1.
CVE-2022-47185 7.5 - High - August 09, 2023

Improper input validation vulnerability on the range header in Apache Software Foundation Apache Traffic Server.This issue affects Apache Traffic Server: through 9.2.1.

Improper Input Validation

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Software Foundation Apache Traffic Server.This issue affects Apache Traffic Server: 8.0.0 to 9.2.0.
CVE-2022-47184 7.5 - High - June 14, 2023

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Software Foundation Apache Traffic Server.This issue affects Apache Traffic Server: 8.0.0 to 9.2.0.

Information Disclosure

Improper Input Validation vulnerability in Apache Software Foundation Apache Traffic Server
CVE-2023-30631 7.5 - High - June 14, 2023

Improper Input Validation vulnerability in Apache Software Foundation Apache Traffic Server.  The configuration option proxy.config.http.push_method_enabled didn't function.  However, by default the PUSH method is blocked in the ip_allow configuration file.This issue affects Apache Traffic Server: from 8.0.0 through 9.2.0. 8.x users should upgrade to 8.1.7 or later versions 9.x users should upgrade to 9.2.1 or later versions

Improper Input Validation

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Software Foundation Apache Traffic Server.This issue affects Apache Traffic Server:
CVE-2023-33933 7.5 - High - June 14, 2023

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Software Foundation Apache Traffic Server.This issue affects Apache Traffic Server: from 8.0.0 through 9.2.0. 8.x users should upgrade to 8.1.7 or later versions 9.x users should upgrade to 9.2.1 or later versions

Information Disclosure

Improper Input Validation vulnerability for the xdebug plugin in Apache Software Foundation Apache Traffic Server
CVE-2022-40743 6.1 - Medium - December 19, 2022

Improper Input Validation vulnerability for the xdebug plugin in Apache Software Foundation Apache Traffic Server can lead to cross site scripting and cache poisoning attacks.This issue affects Apache Traffic Server: 9.0.0 to 9.1.3. Users should upgrade to 9.1.4 or later versions.

XSS

Improper Check for Unusual or Exceptional Conditions vulnerability handling requests in Apache Traffic Server
CVE-2022-32749 7.5 - High - December 19, 2022

Improper Check for Unusual or Exceptional Conditions vulnerability handling requests in Apache Traffic Server allows an attacker to crash the server under certain conditions. This issue affects Apache Traffic Server: from 8.0.0 through 9.1.3.

Improper Check for Unusual or Exceptional Conditions

Improper Check for Unusual or Exceptional Conditions vulnerability in handling the requests to Apache Traffic Server
CVE-2022-37392 5.3 - Medium - December 19, 2022

Improper Check for Unusual or Exceptional Conditions vulnerability in handling the requests to Apache Traffic Server. This issue affects Apache Traffic Server 8.0.0 to 9.1.2.

Improper Check for Unusual or Exceptional Conditions

Improper Input Validation vulnerability in header parsing of Apache Traffic Server allows an attacker to request secure resources
CVE-2021-37150 7.5 - High - August 10, 2022

Improper Input Validation vulnerability in header parsing of Apache Traffic Server allows an attacker to request secure resources. This issue affects Apache Traffic Server 8.0.0 to 9.1.2.

Improper Input Validation

Improper Input Validation vulnerability in HTTP/2 request validation of Apache Traffic Server
CVE-2022-25763 6.8 - Medium - August 10, 2022

Improper Input Validation vulnerability in HTTP/2 request validation of Apache Traffic Server allows an attacker to create smuggle or cache poison attacks. This issue affects Apache Traffic Server 8.0.0 to 9.1.2.

HTTP Request Smuggling

Improper Input Validation vulnerability in HTTP/1.1 header parsing of Apache Traffic Server allows an attacker to send invalid headers
CVE-2022-28129 7.5 - High - August 10, 2022

Improper Input Validation vulnerability in HTTP/1.1 header parsing of Apache Traffic Server allows an attacker to send invalid headers. This issue affects Apache Traffic Server 8.0.0 to 9.1.2.

Improper Input Validation

Improper Input Validation vulnerability in handling the Transfer-Encoding header of Apache Traffic Server
CVE-2022-31778 7.5 - High - August 10, 2022

Improper Input Validation vulnerability in handling the Transfer-Encoding header of Apache Traffic Server allows an attacker to poison the cache. This issue affects Apache Traffic Server 8.0.0 to 9.0.2.

Improper Input Validation

Improper Input Validation vulnerability in HTTP/2 header parsing of Apache Traffic Server allows an attacker to smuggle requests
CVE-2022-31779 7.5 - High - August 10, 2022

Improper Input Validation vulnerability in HTTP/2 header parsing of Apache Traffic Server allows an attacker to smuggle requests. This issue affects Apache Traffic Server 8.0.0 to 9.1.2.

Improper Input Validation

Improper Input Validation vulnerability in HTTP/2 frame handling of Apache Traffic Server allows an attacker to smuggle requests
CVE-2022-31780 7.5 - High - August 10, 2022

Improper Input Validation vulnerability in HTTP/2 frame handling of Apache Traffic Server allows an attacker to smuggle requests. This issue affects Apache Traffic Server 8.0.0 to 9.1.2.

Improper Input Validation

Improper Input Validation vulnerability in request line parsing of Apache Traffic Server allows an attacker to send invalid requests
CVE-2021-44040 7.5 - High - March 23, 2022

Improper Input Validation vulnerability in request line parsing of Apache Traffic Server allows an attacker to send invalid requests. This issue affects Apache Traffic Server 8.0.0 to 8.1.3 and 9.0.0 to 9.1.1.

Improper Input Validation

Improper Authentication vulnerability in TLS origin validation of Apache Traffic Server
CVE-2021-44759 8.1 - High - March 23, 2022

Improper Authentication vulnerability in TLS origin validation of Apache Traffic Server allows an attacker to create a man in the middle attack. This issue affects Apache Traffic Server 8.0.0 to 8.1.0.

authentification

Improper Input Validation vulnerability in accepting socket connections in Apache Traffic Server
CVE-2021-41585 7.5 - High - November 03, 2021

Improper Input Validation vulnerability in accepting socket connections in Apache Traffic Server allows an attacker to make the server stop accepting new connections. This issue affects Apache Traffic Server 5.0.0 to 9.1.0.

Improper Input Validation

Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in the stats-over-http plugin of Apache Traffic Server
CVE-2021-43082 9.8 - Critical - November 03, 2021

Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in the stats-over-http plugin of Apache Traffic Server allows an attacker to overwrite memory. This issue affects Apache Traffic Server 9.1.0.

Classic Buffer Overflow

Improper input validation vulnerability in header parsing of Apache Traffic Server allows an attacker to smuggle requests
CVE-2021-37147 7.5 - High - November 03, 2021

Improper input validation vulnerability in header parsing of Apache Traffic Server allows an attacker to smuggle requests. This issue affects Apache Traffic Server 8.0.0 to 8.1.2 and 9.0.0 to 9.1.0.

Improper Input Validation

Improper input validation vulnerability in header parsing of Apache Traffic Server allows an attacker to smuggle requests
CVE-2021-37148 7.5 - High - November 03, 2021

Improper input validation vulnerability in header parsing of Apache Traffic Server allows an attacker to smuggle requests. This issue affects Apache Traffic Server 8.0.0 to 8.1.2 and 9.0.0 to 9.0.1.

Improper Input Validation

Improper Input Validation vulnerability in header parsing of Apache Traffic Server allows an attacker to smuggle requests
CVE-2021-37149 7.5 - High - November 03, 2021

Improper Input Validation vulnerability in header parsing of Apache Traffic Server allows an attacker to smuggle requests. This issue affects Apache Traffic Server 8.0.0 to 8.1.2 and 9.0.0 to 9.1.0.

Improper Input Validation

Improper Authentication vulnerability in TLS origin verification of Apache Traffic Server allows for man in the middle attacks
CVE-2021-38161 8.1 - High - November 03, 2021

Improper Authentication vulnerability in TLS origin verification of Apache Traffic Server allows for man in the middle attacks. This issue affects Apache Traffic Server 8.0.0 to 8.0.8.

authentification

Improper Input Validation vulnerability in HTTP/2 of Apache Traffic Server allows an attacker to DOS the server
CVE-2021-32566 7.5 - High - June 30, 2021

Improper Input Validation vulnerability in HTTP/2 of Apache Traffic Server allows an attacker to DOS the server. This issue affects Apache Traffic Server 7.0.0 to 7.1.12, 8.0.0 to 8.1.1, 9.0.0 to 9.0.1.

Improper Input Validation

Improper Input Validation vulnerability in HTTP/2 of Apache Traffic Server allows an attacker to DOS the server
CVE-2021-32567 7.5 - High - June 30, 2021

Improper Input Validation vulnerability in HTTP/2 of Apache Traffic Server allows an attacker to DOS the server. This issue affects Apache Traffic Server 7.0.0 to 7.1.12, 8.0.0 to 8.1.1, 9.0.0 to 9.0.1.

Improper Input Validation

Stack-based Buffer Overflow vulnerability in cachekey plugin of Apache Traffic Server
CVE-2021-35474 9.8 - Critical - June 30, 2021

Stack-based Buffer Overflow vulnerability in cachekey plugin of Apache Traffic Server. This issue affects Apache Traffic Server 7.0.0 to 7.1.12, 8.0.0 to 8.1.1, 9.0.0 to 9.0.1.

Memory Corruption

Incorrect handling of url fragment vulnerability of Apache Traffic Server allows an attacker to poison the cache
CVE-2021-27577 7.5 - High - June 29, 2021

Incorrect handling of url fragment vulnerability of Apache Traffic Server allows an attacker to poison the cache. This issue affects Apache Traffic Server 7.0.0 to 7.1.12, 8.0.0 to 8.1.1, 9.0.0 to 9.0.1.

HTTP Request Smuggling

Invalid values in the Content-Length header sent to Apache Traffic Server allows an attacker to smuggle requests
CVE-2021-32565 7.5 - High - June 29, 2021

Invalid values in the Content-Length header sent to Apache Traffic Server allows an attacker to smuggle requests. This issue affects Apache Traffic Server 7.0.0 to 7.1.12, 8.0.0 to 8.1.1, 9.0.0 to 9.0.1.

HTTP Request Smuggling

Apache Traffic Server 9.0.0 is vulnerable to a remote DOS attack on the experimental Slicer plugin.
CVE-2021-27737 7.5 - High - May 14, 2021

Apache Traffic Server 9.0.0 is vulnerable to a remote DOS attack on the experimental Slicer plugin.

ATS negative cache option is vulnerable to a cache poisoning attack
CVE-2020-17509 7.5 - High - January 11, 2021

ATS negative cache option is vulnerable to a cache poisoning attack. If you have this option enabled, please upgrade or disable this feature. Apache Traffic Server versions 7.0.0 to 7.1.11 and 8.0.0 to 8.1.0 are affected.

HTTP Request Smuggling

The ATS ESI plugin has a memory disclosure vulnerability
CVE-2020-17508 7.5 - High - January 11, 2021

The ATS ESI plugin has a memory disclosure vulnerability. If you are running the plugin please upgrade. Apache Traffic Server versions 7.0.0 to 7.1.11 and 8.0.0 to 8.1.0 are affected.

Information Disclosure

Apache Traffic Server 6.0.0 to 6.2.3, 7.0.0 to 7.1.10, and 8.0.0 to 8.0.7 is vulnerable to certain types of HTTP/2 HEADERS frames
CVE-2020-9494 7.5 - High - June 24, 2020

Apache Traffic Server 6.0.0 to 6.2.3, 7.0.0 to 7.1.10, and 8.0.0 to 8.0.7 is vulnerable to certain types of HTTP/2 HEADERS frames that can cause the server to allocate a large amount of memory and spin the thread.

Buffer Overflow

Apache ATS 6.0.0 to 6.2.3
CVE-2020-9481 7.5 - High - April 27, 2020

Apache ATS 6.0.0 to 6.2.3, 7.0.0 to 7.1.9, and 8.0.0 to 8.0.6 is vulnerable to a HTTP/2 slow read attack.

Resource Exhaustion

Stay on top of Security Vulnerabilities

Want an email whenever new vulnerabilities are published for Apache Traffic Server or by Apache? Click the Watch button to subscribe.

Apache
Vendor

subscribe