Traffic Server Apache Traffic Server

Don't miss out!

Thousands of developers use stack.watch to stay informed.
Get an email whenever new security vulnerabilities are reported in Apache Traffic Server.

By the Year

In 2026 there have been 41 vulnerabilities in Apache Traffic Server with an average score of 7.5 out of ten. Last year, in 2025 Traffic Server had 7 security vulnerabilities published. That is, 34 more vulnerabilities have already been reported in 2026 as compared to last year.




Year Vulnerabilities Average Score
2026 41 7.52
2025 7 0.00
2024 8 7.91
2023 8 7.70
2022 11 7.16
2021 14 7.93
2020 5 9.80
2019 10 7.50
2018 7 7.50

It may take a day or so for new Traffic Server vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.

Recent Apache Traffic Server Security Vulnerabilities

Apache Traffic Server HPACK sync bug 8.x-10.1.3
CVE-2026-65100 4.8 - Medium - July 29, 2026

Apache Traffic Server updates the HTTP/2 HPACK dynamic table before confirming the header block encoded successfully, so an encode failure leaves the encoder out of sync with the peer decoder and corrupts subsequent header blocks on the connection. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.

Incorrect Behavior Order

Apache Traffic Server SSRF Amplification via RedirectLimit Bypass (8.0.010.1.3)
CVE-2026-58189 7.5 - High - July 29, 2026

Apache Traffic Server allows redirect-limit bypass when plugins reset the retry counter, enabling SSRF amplification. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.

SSRF

Apache Traffic Server 8.0.0-10.1.3 Experimental Plugins: Mem-Safety LBRB Errors
CVE-2026-58188 8.2 - High - July 29, 2026

Several Apache Traffic Server experimental plugins have memory-safety and limit-bypass errors. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.

Memory Corruption

Apache Traffic Server Chunk-Decode Buffer Overflow in Multi-Plugin (10.1.3)
CVE-2026-58187 3.7 - Low - July 29, 2026

The Apache Traffic Server multiplexer plugin overruns its chunk-decode buffer on upstream input, enabling denial of service. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.

Memory Corruption

Apache Traffic Server 8.x-10.x webp_transform Unsafely Decode & Cacheable Response
CVE-2026-58186 7.5 - High - July 29, 2026

The Apache Traffic Server webp_transform plugin can decode unsafely and serve mislabeled, cacheable responses. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.

Improper Input Validation

Apache Traffic Server 8-10 Use-After-Free in Intercept Plugin
CVE-2026-58185 5.9 - Medium - July 29, 2026

The Apache Traffic Server intercept plugin has a use-after-free. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.

Dangling pointer

Apache Traffic Server header_rewrite Crash/Memory Corruption Before 10.1.4
CVE-2026-58184 8.2 - High - July 29, 2026

The Apache Traffic Server header_rewrite plugin can crash or corrupt memory during cookie operations and CIDR condition matching. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.

Memory Corruption

Apache TS Prefetch Plug Crash v8.0.0-8.1.9 & v9.0.0-9.2.14 & v10.0.0-10.1.3
CVE-2026-58183 5.9 - Medium - July 29, 2026

The Apache Traffic Server prefetch plugin can crash when processing attacker-influenced input. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.

Improper Input Validation

Apache Traffic Server TS_LUA init/ctx/state bug (v8-10)
CVE-2026-58182 8.6 - High - July 29, 2026

The Apache Traffic Server ts_lua plugin mishandles initialization, transform context, and per-instance state. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.

Resource Exhaustion

Apache TS uri_signing/url_sig Stack Crash CVE-2026-58181 8.0.0-10.1.3
CVE-2026-58181 7.5 - High - July 29, 2026

The Apache Traffic Server uri_signing and url_sig plugins can exhaust the stack or crash on attacker input. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.

Stack Overflow

Stack Overflow in Traffic Server txn_box (<=9.2.14)/<=10.1.3, 8.x-8.1.9
CVE-2026-58180 7.5 - High - July 29, 2026

The Apache Traffic Server txn_box plugin overflows the stack from attacker-controlled input. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.

Stack Overflow

Stack Overflow in regex_remap Plugin on Apache Traffic Server (8.0-10.1)
CVE-2026-58179 8.1 - High - July 29, 2026

The Apache Traffic Server regex_remap plugin overflows the stack and integers from substitution input. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.

Stack Overflow

Apache TS ESI: Recursion Fetch Attacker URLs (v8-8.1.9/9-9.2.14/10-10.1.3)
CVE-2026-58178 7.5 - High - July 29, 2026

The Apache Traffic Server ESI plugin can recurse without bound and fetch attacker-controlled URLs. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.

Stack Exhaustion

Apache Traffic Server 10.010.1.3 Cripts: OOB Write, Path Traversal, UAF
CVE-2026-58177 8.1 - High - July 29, 2026

The Apache Traffic Server Cripts framework has out-of-bounds writes, path traversal, and use-after-free errors. This issue affects Apache Traffic Server: from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 10.1.4, which fix the issue.

Memory Corruption

Apache Traffic Server Memory Leak (HostDB SRV) up to 10.1.3
CVE-2026-58175 7.5 - High - July 29, 2026

Apache Traffic Server leaks memory when handling HostDB SRV records. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.

Memory Leak

Apache Traffic Server 8.0-10.1.3 UA/TOU in remap config
CVE-2026-58164 7.5 - High - July 29, 2026

Apache Traffic Server has use-after-free and time-of-check/time-of-use errors in remap configuration handling. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.

Dangling pointer

Apache Traffic Server Cache Field Corruption Crash (v8.0.0-10.1.3)
CVE-2026-58163 7.5 - High - July 29, 2026

Apache Traffic Server mishandles on-disk cache fields and object lifetimes, corrupting state or crashing. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.

Marshaling, Unmarshaling

Apache Traffic Server SNI-based Cert Injection <8.0.0-10.1.3
CVE-2026-58162 10 - Critical - July 29, 2026

The Apache Traffic Server certifier plugin generates certificates based on attacker-controlled client SNI. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.

Improper Certificate Validation

Apache Traffic Server Null Deref Crash in TLS/SNI (8.0.010.1.3)
CVE-2026-58161 7.5 - High - July 29, 2026

Apache Traffic Server can crash from null dereferences and dangling references in TLS and SNI handling. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.

NULL Pointer Dereference

TrfServ OOB DNS Read CVE-2026-58160 (8.08.1.9, 9.09.2.14, 10.010.1.3)
CVE-2026-58160 6.5 - Medium - July 29, 2026

Apache Traffic Server reads out of bounds while parsing DNS answers. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.

Out-of-bounds Read

Apache Traffic Server IP ACL Bypass on UDS Listeners (fix in 9.2.15 /10.1.4)
CVE-2026-58159 8.2 - High - July 29, 2026

Apache Traffic Server can bypass IP access controls on UDS listeners and through ACL matching errors. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.

AuthZ

Apache Traffic Server PROXY Protocol Stack Overflow 8.0-10.1 fixed 9.2.15/10.1.4
CVE-2026-58158 5.9 - Medium - July 29, 2026

Apache Traffic Server mishandles PROXY protocol input, truncating ports and overflowing the stack. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.

Stack Overflow

Apache TS Improper Session/Tunnel Reuse Exposes Data (8.0.010.1.3)
CVE-2026-58157 8.7 - High - July 29, 2026

Apache Traffic Server can reuse server sessions and tunnels improperly, exposing data across client connections. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.

Information Disclosure

Apache Traffic Server Port Parsing Bypass (8.0.08.1.9, 9.0.09.2.14, 10.0.010.1.3)
CVE-2026-58156 4.9 - Medium - July 29, 2026

Apache Traffic Server mis-parses ports in URLs and userinfo, allowing port-based access-control bypass. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.

AuthZ

Apache Traffic Server Header Alias Bypass (8.0-10.1.3)
CVE-2026-58155 9.3 - Critical - July 29, 2026

Apache Traffic Server truncates over-long header names, allowing header aliasing, request smuggling, and policy bypass. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.

HTTP Request Smuggling

Apache Traffic Server OOB Write in header parsing v810
CVE-2026-58154 8.9 - High - July 29, 2026

Apache Traffic Server can write out of bounds or overflow integers while parsing MIME and HTTP headers. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.

Memory Corruption

Apache Traffic Server HTTP/2 conn. reuse lacking cert check v9.0-10.1
CVE-2026-65325 4.8 - Medium - July 29, 2026

Apache Traffic Server reuses multiplexed HTTP/2 origin connections without verifying the server certificate covers the new request hostname. This issue affects Apache Traffic Server: from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.

Improper Certificate Validation

Apache Traffic Server 8.x-10.1.3: HTTP/2/3 Dechunking Causing Mem Exhaustion
CVE-2026-65324 7.5 - High - July 29, 2026

Apache Traffic Server drops the per-stream buffer cap when dechunking HTTP/2 or HTTP/3 responses, letting a slow client exhaust server memory. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.

Resource Exhaustion

Apache Traffic Server 10.0.0-10.1.3 HTTP/2 trailers -> HTTP/1 chunk framing bug
CVE-2026-58153 8.3 - High - July 29, 2026

Apache Traffic Server forwards HTTP/2 origin trailers to HTTP/1 clients without proper chunked framing when converting HTTP/2 to HTTP/1. This issue affects Apache Traffic Server: from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.

HTTP Request Smuggling

Apache Traffic Server Int Overrun in HPACK/XPACK Headers 8.0.0-8.1.9/9.0.0-9.2.14/10.0.0-10.1.3
CVE-2026-58152 5.9 - Medium - July 29, 2026

Apache Traffic Server mishandles integers while decoding HPACK/XPACK headers, corrupting memory. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.

Integer Overflow or Wraparound

Apache Traffic Server 8.0.0-10.1.3: Crash via Abusive HTTP/2 Framing
CVE-2026-58151 7.5 - High - July 29, 2026

Apache Traffic Server can be crashed or driven to resource exhaustion by abusive HTTP/2 framing and flow-control. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.

Resource Exhaustion

Traffic Server: HTTP/2 Transfer-Encoding downgrade smuggling, v8.010.1.3
CVE-2026-58150 10 - Critical - July 29, 2026

Apache Traffic Server does not reject Transfer-Encoding in HTTP/2 requests, allowing downgrade request smuggling. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.

HTTP Request Smuggling

Apache Traffic Server (ATS) Chunked Req Smuggling 8.0.010.1.3
CVE-2026-57834 10 - Critical - July 29, 2026

Apache Traffic Server allows request smuggling if chunked messages are malformed. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.

HTTP Request Smuggling

Apache Traffic Server Host Header stack overflow in redirect (8.0.0-10.1.3)
CVE-2026-33930 5.9 - Medium - July 29, 2026

Apache Traffic Server copies the client Host header into a fixed-size stack buffer without a bound during redirect handling, so an over-long Host header overflows the stack when redirect following is enabled. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.

Stack Overflow

Apache Traffic Server HTTP Request Smuggling (9.0.0-9.2.14, 10.0.0-10.1.3)
CVE-2026-24033 7.2 - High - July 29, 2026

Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') vulnerability in Apache Traffic Server. This issue affects Apache Traffic Server: from 10.0.0 through 10.1.3, from 9.0.0 through 9.2.14. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fixes the issue.

HTTP Request Smuggling

Improper Input Validation in Apache Traffic Server (ATS) v9.2.09.2.14 & v10.1.010.1.3
CVE-2026-33267 10 - Critical - July 29, 2026

Improper Input Validation vulnerability in Apache Traffic Server. This issue affects Apache Traffic Server: from 9.2.0 through 9.2.14, from 10.1.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fixes the issue.

Improper Input Validation

Apache Traffic Server <10.1.4 vulnerable to REGEXP no anchor CVE-2026-22068
CVE-2026-22068 8.2 - High - July 29, 2026

Regular Expression without Anchors vulnerability in Apache Traffic Server. This issue affects Apache Traffic Server: from 10.0.X through 10.1.3, from 9.0.X through 9.2.14. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fixes the issue.

Regular Expression without Anchors

Apache Traffic Server 9.x/10.x Improper Access Control <9.1.15 /10.1.4
CVE-2026-41920 9.3 - Critical - July 29, 2026

Improper Access Control vulnerability in Apache Traffic Server. This issue affects Apache Traffic Server: from 9.0.0 through 9.1.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.1.15 or 10.1.4, which fixes the issue.

Authorization

Apache Traffic Server Uncontrolled Resource Consumption ( 9.1.13, 10.1.2)
CVE-2026-59173 7.5 - High - July 18, 2026

Uncontrolled Resource Consumption vulnerability in Apache Traffic Server. This issue affects Apache Traffic Server: from 9.0.0 through 9.1.13, from 10.0.0 through 10.1.2. Users are recommended to upgrade to version 9.1.14 or 10.1.3, which fixes the issue.

Resource Exhaustion

Apache Traffic Server <9.2.13 or <10.1.2 Chunked Msg Request Smuggling
CVE-2025-65114 7.5 - High - April 02, 2026

Apache Traffic Server allows request smuggling if chunked messages are malformed.  This issue affects Apache Traffic Server: from 9.0.0 through 9.2.12, from 10.0.0 through 10.1.1. Users are recommended to upgrade to version 9.2.13 or 10.1.2, which fix the issue.

HTTP Request Smuggling

Apache Traffic Server POST handling crash before 10.1.2/9.2.13
CVE-2025-58136 7.5 - High - April 02, 2026

A bug in POST request handling causes a crash under a certain condition. This issue affects Apache Traffic Server: from 10.0.0 through 10.1.1, from 9.0.0 through 9.2.12. Users are recommended to upgrade to version 10.1.2 or 9.2.13, which fix the issue. A workaround for older versions is to set proxy.config.http.request_buffer_enabled to 0 (the default value is 0).

Always-Incorrect Control Flow Implementation

Apache Traffic Server ACL ignores PROXY IP – CVE-2025-31698
CVE-2025-31698 - June 19, 2025

ACL configured in ip_allow.config or remap.config does not use IP addresses that are provided by PROXY protocol. Users can use a new setting (proxy.config.acl.subjects) to choose which IP addresses to use for the ACL if Apache Traffic Server is configured to accept PROXY protocol.  This issue affects undefined: from 10.0.0 through 10.0.6, from 9.0.0 through 9.2.10. Users are recommended to upgrade to version 9.2.11 or 10.0.6, which fixes the issue.

Authorization

Apache Traffic Server ESI Plugin Depth Oops: Memory Overload (v10)
CVE-2025-49763 - June 19, 2025

ESI plugin does not have the limit for maximum inclusion depth, and that allows excessive memory consumption if malicious instructions are inserted. Users can use a new setting for the plugin (--max-inclusion-depth) to limit it. This issue affects Apache Traffic Server: from 10.0.0 through 10.0.5, from 9.0.0 through 9.2.10. Users are recommended to upgrade to version 9.2.11 or 10.0.6, which fixes the issue.

Resource Exhaustion

Apache Traffic Server 9.2.x/10.x request smuggling via malformed chunks
CVE-2024-53868 - April 03, 2025

Apache Traffic Server allows request smuggling if chunked messages are malformed.  This issue affects Apache Traffic Server: from 9.2.0 through 9.2.9, from 10.0.0 through 10.0.4. Users are recommended to upgrade to version 9.2.10 or 10.0.5, which fixes the issue.

HTTP Request Smuggling

Apache Traffic Server <=10.0.3 Improper Access Control
CVE-2024-56195 - March 06, 2025

Improper Access Control vulnerability in Apache Traffic Server. This issue affects Apache Traffic Server: from 9.2.0 through 9.2.8, from 10.0.0 through 10.0.3. Users are recommended to upgrade to version 9.2.9 or 10.0.4, which fixes the issue.

Authorization

Apache Traffic Server 10.0.0-10.0.3 IAC Vulnerability
CVE-2024-56196 - March 06, 2025

Improper Access Control vulnerability in Apache Traffic Server. This issue affects Apache Traffic Server: from 10.0.0 through 10.0.3. Users are recommended to upgrade to version 10.0.4, which fixes the issue.

Authorization

Apache Traffic Server Improper Input Validation in 8-10.x Versions
CVE-2024-38311 - March 06, 2025

Improper Input Validation vulnerability in Apache Traffic Server. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.11, from 9.0.0 through 9.2.8, from 10.0.0 through 10.0.3. Users are recommended to upgrade to version 9.2.9 or 10.0.4, which fixes the issue.

Improper Input Validation

Apache Traffic Server EBV Vulnerability (9.0.0-9.2.8 & 10.0.0-10.0.3)
CVE-2024-56202 - March 06, 2025

Expected Behavior Violation vulnerability in Apache Traffic Server. This issue affects Apache Traffic Server: from 9.0.0 through 9.2.8, from 10.0.0 through 10.0.3. Users are recommended to upgrade to versions 9.2.9 or 10.0.4 or newer, which fixes the issue.

Expected Behavior Violation

Bluetooth Service Integer Overflow Vulnerability in Android
CVE-2018-9481 6.5 - Medium - November 20, 2024

In bta_hd_set_report_act of bta_hd_act.cc, there is a possible out-of-bounds read due to an integer overflow. This could lead to remote information disclosure in the Bluetooth service with no additional execution privileges needed. User interaction is not needed for exploitation.

Integer Overflow or Wraparound

Apache Traffic Server: HTTP Header Parsing Vulnerability
CVE-2024-50305 - November 14, 2024

Valid Host header field can cause Apache Traffic Server to crash on some platforms. This issue affects Apache Traffic Server: from 9.2.0 through 9.2.5. Users are recommended to upgrade to version 9.2.6, which fixes the issue, or 10.0.2, which does not have the issue.

Improper Input Validation

Stay on top of Security Vulnerabilities

Want an email whenever new vulnerabilities are published for Apache Traffic Server or by Apache? Click the Watch button to subscribe.

Apache
Vendor

subscribe