Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1310 CNY

100%

Apache Traffic Server — Vulnerabilities & Security Advisories 63

All 63 CVE vulnerabilities found in Apache Traffic Server, with AI-generated Chinese analysis, references, and POCs.

This page provides a comprehensive aggregation of known security vulnerabilities for Apache Traffic Server, focusing on common weakness enumeration categories and associated tags. It collects data regarding various types of security flaws, including buffer overflows, injection vulnerabilities, configuration errors, and logic errors, covering historical records and recent disclosures up to the present date. By utilizing this resource, users can effectively track advisories issued by the Apache Software Foundation, gain a deeper understanding of specific weakness classes affecting distributed caching systems, and review the complete vulnerability history of this particular product to assess risk exposure. The aggregated information is structured to facilitate efficient analysis for security professionals, system administrators, and developers who rely on Apache Traffic Server for high-performance caching and proxy services. Each entry includes contextual details that help in prioritizing remediation efforts and applying necessary patches or configuration changes. This centralized view eliminates the need to search through multiple disparate sources, ensuring that all relevant security updates and flaw reports are accessible in one location. The data reflects the evolving threat landscape and the continuous efforts to secure open-source web infrastructure. Readers are encouraged to cross-reference these details with official documentation and vendor notifications to maintain a robust security posture. This page serves as a critical reference point for evaluating the integrity and safety of Apache Traffic Server deployments in enterprise and production environments.

Vendor: Apache Software Foundation

CVE IDTitleCVSSSeverityPublished
CVE-2022-31778 Transfer-Encoding not treated as hop-by-hop CWE-20 7.5 -2022-08-10
CVE-2022-28129 Insufficient Validation of HTTP/1.x Headers CWE-20 7.5 -2022-08-10
CVE-2021-44759 Improper authentication vulnerability in TLS origin verification CWE-287 7.7 -2022-03-23
CVE-2021-44040 HTTP request line fuzzing attacks CWE-20 7.5 -2022-03-23
CVE-2021-43082 heap-buffer-overflow with stats-over-http plugin CWE-120 9.8 -2021-11-03
CVE-2021-41585 ATS stops accepting connections on FreeBSD 7.5 -2021-11-03
CVE-2021-38161 Not validating origin TLS certificate CWE-287 7.7 -2021-11-03
CVE-2021-37149 Request Smuggling - multiple attacks CWE-20 7.5 -2021-11-03
CVE-2021-37148 Request Smuggling - transfer encoding validation CWE-20 7.5 -2021-11-03
CVE-2021-37147 Request Smuggling - LF line ending CWE-20 7.5 -2021-11-03
CVE-2021-35474 Dynamic stack buffer overflow in cachekey plugin CWE-121 9.8 -2021-06-30
CVE-2021-32567 Reading HTTP/2 frames too many times CWE-20 7.5 -2021-06-30
CVE-2021-32566 Specific sequence of HTTP/2 frames can cause ATS to crash CWE-20 7.5 -2021-06-30
CVE-2021-32565 HTTP Request Smuggling, content length with invalid charters CWE-444 7.5 -2021-06-29
CVE-2021-27577 Incorrect handling of url fragment leads to cache poisoning CWE-444 7.5 -2021-06-29
CVE-2021-27737 Apache Traffic Server 安全漏洞 7.5 -2021-05-14
CVE-2020-17508 Apache Traffic Server 信息泄露漏洞 7.5 -2021-01-11
CVE-2020-17509 Apache Traffic Server 环境问题漏洞 7.5 -2021-01-11
CVE-2020-9494 Apache Traffic Server 缓冲区错误漏洞 7.5 -2020-06-24
CVE-2020-1944 Apache Traffic Server 环境问题漏洞 9.8 -2020-03-23
CVE-2019-17559 Apache Traffic Server 环境问题漏洞 9.1 -2020-03-23
CVE-2019-17565 Apache Traffic Server 环境问题漏洞 9.8 -2020-03-23
CVE-2019-10079 Apache Traffic Server 输入验证错误漏洞 7.5 -2019-10-22
CVE-2018-11783 Apache Traffic Server 信息泄露漏洞 6.5 -2019-03-07
CVE-2018-8040 Apache Traffic Server 安全漏洞 5.3 -2018-08-29
CVE-2018-8022 Apache Traffic Server 安全漏洞 7.5 -2018-08-29
CVE-2018-8005 Apache Traffic Server 安全漏洞 8.2 -2018-08-29
CVE-2018-8004 Apache Traffic Server 安全漏洞 7.5 -2018-08-29
CVE-2018-1318 Apache Traffic Server 安全漏洞 7.5 -2018-08-29
CVE-2017-7671 Apache Traffic Server 安全漏洞 7.5 -2018-02-27

All 63 known CVE vulnerabilities affecting Apache Traffic Server with full Chinese analysis, references, and POCs where available.