apache / traffic_server
41 known vulnerabilities in apache traffic_server.
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2026-59173 | Medium | 0.7% | 7.5 | Uncontrolled Resource Consumption vulnerability in Apache Traffic Server. This … | |
| CVE-2025-58136 | Medium | 0.7% | 7.5 | A bug in POST request handling causes a crash under a certain condition. This i… | |
| CVE-2026-58151 | Medium | 0.5% | 7.5 | Apache Traffic Server can be crashed or driven to resource exhaustion by abusive… | |
| CVE-2026-65324 | Medium | 0.5% | 7.5 | Apache Traffic Server drops the per-stream buffer cap when dechunking HTTP/2 or … | |
| CVE-2026-58153 | Medium | 0.5% | 8.3 | Apache Traffic Server forwards HTTP/2 origin trailers to HTTP/1 clients without … | |
| CVE-2026-58161 | Medium | 0.4% | 7.5 | Apache Traffic Server can crash from null dereferences and dangling references i… | |
| CVE-2026-58188 | Medium | 0.4% | 8.2 | Several Apache Traffic Server experimental plugins have memory-safety and limit-… | |
| CVE-2025-65114 | Medium | 0.4% | 7.5 | Apache Traffic Server allows request smuggling if chunked messages are malformed… | |
| CVE-2026-58182 | Medium | 0.4% | 8.6 | The Apache Traffic Server ts_lua plugin mishandles initialization, transform con… | |
| CVE-2026-58186 | Medium | 0.4% | 7.5 | The Apache Traffic Server webp_transform plugin can decode unsafely and serve mi… | |
| CVE-2026-22068 | Medium | 0.4% | 8.2 | Regular Expression without Anchors vulnerability in Apache Traffic Server. This… | |
| CVE-2026-58155 | Medium | 0.4% | 9.3 | Apache Traffic Server truncates over-long header names, allowing header aliasing… | |
| CVE-2026-58175 | Medium | 0.4% | 7.5 | Apache Traffic Server leaks memory when handling HostDB SRV records. This issue… | |
| CVE-2026-58178 | Medium | 0.4% | 7.5 | The Apache Traffic Server ESI plugin can recurse without bound and fetch attacke… | |
| CVE-2026-58180 | Medium | 0.4% | 7.5 | The Apache Traffic Server txn_box plugin overflows the stack from attacker-contr… | |
| CVE-2026-58154 | Medium | 0.4% | 8.9 | Apache Traffic Server can write out of bounds or overflow integers while parsing… | |
| CVE-2026-58164 | Medium | 0.4% | 7.5 | Apache Traffic Server has use-after-free and time-of-check/time-of-use errors in… | |
| CVE-2026-58181 | Medium | 0.4% | 7.5 | The Apache Traffic Server uri_signing and url_sig plugins can exhaust the stack … | |
| CVE-2026-58163 | Medium | 0.4% | 7.5 | Apache Traffic Server mishandles on-disk cache fields and object lifetimes, corr… | |
| CVE-2026-57834 | Medium | 0.4% | 10.0 | Apache Traffic Server allows request smuggling if chunked messages are malformed… | |
| CVE-2026-33267 | Medium | 0.4% | 10.0 | Improper Input Validation vulnerability in Apache Traffic Server. This issue af… | |
| CVE-2026-58150 | Medium | 0.4% | 10.0 | Apache Traffic Server does not reject Transfer-Encoding in HTTP/2 requests, allo… | |
| CVE-2026-58179 | Medium | 0.4% | 8.1 | The Apache Traffic Server regex_remap plugin overflows the stack and integers fr… | |
| CVE-2026-58189 | Medium | 0.4% | 7.5 | Apache Traffic Server allows redirect-limit bypass when plugins reset the retry … | |
| CVE-2026-58184 | Medium | 0.3% | 8.2 | The Apache Traffic Server header_rewrite plugin can crash or corrupt memory duri… | |
| CVE-2026-58177 | Medium | 0.3% | 8.1 | The Apache Traffic Server Cripts framework has out-of-bounds writes, path traver… | |
| CVE-2026-24033 | Medium | 0.3% | 7.2 | Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')… | |
| CVE-2026-58159 | Medium | 0.3% | 8.2 | Apache Traffic Server can bypass IP access controls on UDS listeners and through… | |
| CVE-2026-41920 | Medium | 0.3% | 9.3 | Improper Access Control vulnerability in Apache Traffic Server. This issue affe… | |
| CVE-2026-58157 | Medium | 0.3% | 8.7 | Apache Traffic Server can reuse server sessions and tunnels improperly, exposing… | |
| CVE-2026-58162 | Medium | 0.2% | 10.0 | The Apache Traffic Server certifier plugin generates certificates based on attac… | |
| CVE-2026-58160 | Low | 0.4% | 6.5 | Apache Traffic Server reads out of bounds while parsing DNS answers. This issue… | |
| CVE-2026-58183 | Low | 0.4% | 5.9 | The Apache Traffic Server prefetch plugin can crash when processing attacker-inf… | |
| CVE-2026-33930 | Low | 0.4% | 5.9 | Apache Traffic Server copies the client Host header into a fixed-size stack buff… | |
| CVE-2026-65100 | Low | 0.4% | 4.8 | Apache Traffic Server updates the HTTP/2 HPACK dynamic table before confirming t… | |
| CVE-2026-58152 | Low | 0.3% | 5.9 | Apache Traffic Server mishandles integers while decoding HPACK/XPACK headers, co… | |
| CVE-2026-58158 | Low | 0.3% | 5.9 | Apache Traffic Server mishandles PROXY protocol input, truncating ports and over… | |
| CVE-2026-58187 | Low | 0.3% | 3.7 | The Apache Traffic Server multiplexer plugin overruns its chunk-decode buffer on… | |
| CVE-2026-58185 | Low | 0.3% | 5.9 | The Apache Traffic Server intercept plugin has a use-after-free. This issue aff… | |
| CVE-2026-58156 | Low | 0.2% | 4.9 | Apache Traffic Server mis-parses ports in URLs and userinfo, allowing port-based… | |
| CVE-2026-65325 | Low | 0.2% | 4.8 | Apache Traffic Server reuses multiplexed HTTP/2 origin connections without verif… |