CVE-2026-58151
- EPSS 0.47%
- Veröffentlicht 29.07.2026 08:15:45
- Zuletzt bearbeitet 03.08.2026 13:42:15
Apache Traffic Server can be crashed or driven to resource exhaustion by abusive HTTP/2 framing and flow-control. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are r...
- EPSS 0.32%
- Veröffentlicht 29.07.2026 07:30:25
- Zuletzt bearbeitet 03.08.2026 13:42:21
Apache Traffic Server does not reject Transfer-Encoding in HTTP/2 requests, allowing downgrade request smuggling. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are r...
- EPSS 0.34%
- Veröffentlicht 29.07.2026 07:25:49
- Zuletzt bearbeitet 03.08.2026 13:42:28
Apache Traffic Server allows request smuggling if chunked messages are malformed. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version...
CVE-2026-33930
- EPSS 0.32%
- Veröffentlicht 29.07.2026 07:23:54
- Zuletzt bearbeitet 03.08.2026 13:42:43
Apache Traffic Server copies the client Host header into a fixed-size stack buffer without a bound during redirect handling, so an over-long Host header overflows the stack when redirect following is enabled. This issue affects Apache Traffic Server...
CVE-2026-24033
- EPSS 0.33%
- Veröffentlicht 29.07.2026 07:22:42
- Zuletzt bearbeitet 05.08.2026 20:24:49
Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') vulnerability in Apache Traffic Server. This issue affects Apache Traffic Server: from 10.0.0 through 10.1.3, from 9.0.0 through 9.2.14. Users are recommended to upgra...
CVE-2026-33267
- EPSS 0.34%
- Veröffentlicht 29.07.2026 07:21:52
- Zuletzt bearbeitet 05.08.2026 18:35:55
Improper Input Validation vulnerability in Apache Traffic Server. This issue affects Apache Traffic Server: from 9.2.0 through 9.2.14, from 10.1.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fixes the issue.
CVE-2026-22068
- EPSS 0.35%
- Veröffentlicht 29.07.2026 07:19:04
- Zuletzt bearbeitet 05.08.2026 20:22:41
Regular Expression without Anchors vulnerability in Apache Traffic Server. This issue affects Apache Traffic Server: from 10.0.X through 10.1.3, from 9.0.X through 9.2.14. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fixes th...
CVE-2026-41920
- EPSS 0.3%
- Veröffentlicht 29.07.2026 07:18:01
- Zuletzt bearbeitet 03.08.2026 13:42:36
Improper Access Control vulnerability in Apache Traffic Server. This issue affects Apache Traffic Server: from 9.0.0 through 9.1.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.1.15 or 10.1.4, which fixes the issue.
CVE-2026-59173
- EPSS 0.73%
- Veröffentlicht 18.07.2026 12:52:18
- Zuletzt bearbeitet 06.08.2026 18:30:45
Uncontrolled Resource Consumption vulnerability in Apache Traffic Server. This issue affects Apache Traffic Server: from 9.0.0 through 9.1.13, from 10.0.0 through 10.1.2. Users are recommended to upgrade to version 9.1.14 or 10.1.3, which fixes the...
CVE-2025-65114
- EPSS 0.43%
- Veröffentlicht 02.04.2026 15:55:27
- Zuletzt bearbeitet 24.07.2026 21:10:00
Apache Traffic Server allows request smuggling if chunked messages are malformed. This issue affects Apache Traffic Server: from 9.0.0 through 9.2.12, from 10.0.0 through 10.1.1. Users are recommended to upgrade to version 9.2.13 or 10.1.2, which ...