Apache

Traffic Server

121 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.45%
  • Veröffentlicht 29.07.2026 09:06:17
  • Zuletzt bearbeitet 03.08.2026 19:31:56

Apache Traffic Server updates the HTTP/2 HPACK dynamic table before confirming the header block encoded successfully, so an encode failure leaves the encoder out of sync with the peer decoder and corrupts subsequent header blocks on the connection. ...

  • EPSS 0.49%
  • Veröffentlicht 29.07.2026 09:05:19
  • Zuletzt bearbeitet 03.08.2026 13:38:49

Apache Traffic Server allows redirect-limit bypass when plugins reset the retry counter, enabling SSRF amplification. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users a...

  • EPSS 0.6%
  • Veröffentlicht 29.07.2026 09:04:24
  • Zuletzt bearbeitet 03.08.2026 13:39:15

Several Apache Traffic Server experimental plugins have memory-safety and limit-bypass errors. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgra...

  • EPSS 0.45%
  • Veröffentlicht 29.07.2026 09:03:22
  • Zuletzt bearbeitet 31.07.2026 20:51:17

The Apache Traffic Server multiplexer plugin overruns its chunk-decode buffer on upstream input, enabling denial of service. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. ...

  • EPSS 0.55%
  • Veröffentlicht 29.07.2026 09:01:39
  • Zuletzt bearbeitet 31.07.2026 20:51:59

The Apache Traffic Server webp_transform plugin can decode unsafely and serve mislabeled, cacheable responses. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are reco...

  • EPSS 0.45%
  • Veröffentlicht 29.07.2026 08:57:48
  • Zuletzt bearbeitet 31.07.2026 20:52:12

The Apache Traffic Server intercept plugin has a use-after-free. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4...

  • EPSS 0.46%
  • Veröffentlicht 29.07.2026 08:56:51
  • Zuletzt bearbeitet 31.07.2026 20:52:52

The Apache Traffic Server header_rewrite plugin can crash or corrupt memory during cookie operations and CIDR condition matching. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1...

  • EPSS 0.51%
  • Veröffentlicht 29.07.2026 08:55:52
  • Zuletzt bearbeitet 31.07.2026 20:53:07

The Apache Traffic Server prefetch plugin can crash when processing attacker-influenced input. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgra...

  • EPSS 0.54%
  • Veröffentlicht 29.07.2026 08:54:49
  • Zuletzt bearbeitet 31.07.2026 20:53:21

The Apache Traffic Server ts_lua plugin mishandles initialization, transform context, and per-instance state. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recom...

  • EPSS 0.49%
  • Veröffentlicht 29.07.2026 08:46:04
  • Zuletzt bearbeitet 31.07.2026 20:53:33

The Apache Traffic Server uri_signing and url_sig plugins can exhaust the stack or crash on attacker input. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recomme...