CVE-2025-65114
- EPSS 0.3%
- Veröffentlicht 02.04.2026 15:55:27
- Zuletzt bearbeitet 06.04.2026 16:05:24
Apache Traffic Server allows request smuggling if chunked messages are malformed. This issue affects Apache Traffic Server: from 9.0.0 through 9.2.12, from 10.0.0 through 10.1.1. Users are recommended to upgrade to version 9.2.13 or 10.1.2, which ...
CVE-2025-58136
- EPSS 0.41%
- Veröffentlicht 02.04.2026 15:54:47
- Zuletzt bearbeitet 06.04.2026 16:06:11
A bug in POST request handling causes a crash under a certain condition. This issue affects Apache Traffic Server: from 10.0.0 through 10.1.1, from 9.0.0 through 9.2.12. Users are recommended to upgrade to version 10.1.2 or 9.2.13, which fix the is...
CVE-2025-49763
- EPSS 3.37%
- Veröffentlicht 19.06.2025 10:15:21
- Zuletzt bearbeitet 01.07.2025 20:15:05
ESI plugin does not have the limit for maximum inclusion depth, and that allows excessive memory consumption if malicious instructions are inserted. Users can use a new setting for the plugin (--max-inclusion-depth) to limit it. This issue affects A...
CVE-2025-31698
- EPSS 0.75%
- Veröffentlicht 19.06.2025 10:15:20
- Zuletzt bearbeitet 01.07.2025 20:14:42
ACL configured in ip_allow.config or remap.config does not use IP addresses that are provided by PROXY protocol. Users can use a new setting (proxy.config.acl.subjects) to choose which IP addresses to use for the ACL if Apache Traffic Server is conf...
CVE-2024-53868
- EPSS 0.24%
- Veröffentlicht 03.04.2025 09:15:15
- Zuletzt bearbeitet 29.04.2025 20:42:23
Apache Traffic Server allows request smuggling if chunked messages are malformed. This issue affects Apache Traffic Server: from 9.2.0 through 9.2.9, from 10.0.0 through 10.0.4. Users are recommended to upgrade to version 9.2.10 or 10.0.5, whi...
CVE-2024-56196
- EPSS 0.07%
- Veröffentlicht 06.03.2025 12:15:35
- Zuletzt bearbeitet 07.05.2025 16:36:33
Improper Access Control vulnerability in Apache Traffic Server. This issue affects Apache Traffic Server: from 10.0.0 through 10.0.3. Users are recommended to upgrade to version 10.0.4, which fixes the issue.
CVE-2024-56195
- EPSS 0.06%
- Veröffentlicht 06.03.2025 12:15:35
- Zuletzt bearbeitet 29.04.2025 16:42:01
Improper Access Control vulnerability in Apache Traffic Server. This issue affects Apache Traffic Server: from 9.2.0 through 9.2.8, from 10.0.0 through 10.0.3. Users are recommended to upgrade to version 9.2.9 or 10.0.4, which fixes the issue.
CVE-2024-38311
- EPSS 0.08%
- Veröffentlicht 06.03.2025 12:15:34
- Zuletzt bearbeitet 29.04.2025 16:34:58
Improper Input Validation vulnerability in Apache Traffic Server. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.11, from 9.0.0 through 9.2.8, from 10.0.0 through 10.0.3. Users are recommended to upgrade to version 9.2.9 or 10.0.4...
CVE-2024-56202
- EPSS 0.14%
- Veröffentlicht 06.03.2025 11:15:11
- Zuletzt bearbeitet 29.04.2025 16:41:26
Expected Behavior Violation vulnerability in Apache Traffic Server. This issue affects Apache Traffic Server: from 9.0.0 through 9.2.8, from 10.0.0 through 10.0.3. Users are recommended to upgrade to versions 9.2.9 or 10.0.4 or newer, which fixes t...
CVE-2018-9481
- EPSS 0.09%
- Veröffentlicht 20.11.2024 18:15:19
- Zuletzt bearbeitet 18.12.2024 18:49:52
In bta_hd_set_report_act of bta_hd_act.cc, there is a possible out-of-bounds read due to an integer overflow. This could lead to remote information disclosure in the Bluetooth service with no additional execution privileges needed. User interaction i...