Apache traffic server
This hub aggregates every CVE we track for Apache traffic server, a product in the networking infrastructure space. Use it to gauge the current risk picture and drill into individual advisories.
56
CVEs tracked
4
Critical
43
High
0
In CISA KEV
Severity distribution
HIGH43MEDIUM9CRITICAL4
Monthly trend
3
0
0
0
3
0
0
0
4
1
0
2
0
0
0
0
0
0
0
0
0
2
0
0
2024-072026-06
Latest CVEs
The 15 most recently published vulnerabilities affecting Apache traffic server.
- CVE-2025-65114Apache Traffic Server: Malformed chunked message body allows request smuggling7.5
- CVE-2025-58136Apache Traffic Server: A simple legitimate POST request causes a crash7.5
- CVE-2025-31698Apache Traffic Server: Client IP address from PROXY protocol is not used for ACL7.5
- CVE-2025-49763Apache Traffic Server: Remote DoS via memory exhaustion in ESI Plugin7.5
- CVE-2024-53868Apache Traffic Server: Malformed chunked message body allows request smuggling7.5
- CVE-2024-38311Apache Traffic Server: Request smuggling via pipelining after a chunked message body6.3
- CVE-2024-56195Apache Traffic Server: Intercept plugins are not access controlled6.3
- CVE-2024-56196Apache Traffic Server: ACL is not fully compatible with older versions6.3
- CVE-2024-56202Apache Traffic Server: Expect header field can unreasonably retain resource4.3
- CVE-2024-50306Apache Traffic Server: Server process can fail to drop privilege9.1
- CVE-2024-50305Apache Traffic Server: Valid Host field value can cause crashes7.5
- CVE-2024-38479Apache Traffic Server: Cache key plugin is vulnerable to cache poisoning attack7.5
- CVE-2023-38522Apache Traffic Server: Incomplete field name check allows request smuggling7.5
- CVE-2024-35296Apache Traffic Server: Invalid Accept-Encoding can force forwarding requests8.2
- CVE-2024-35161Apache Traffic Server: Incomplete check for chunked trailer section allows request smuggling7.5
Product normalization is registry-driven with AI assist and human review. How it works