Apache Traffic Server(ATS)是美国阿帕奇(Apache)基金会的一套可扩展的HTTP代理和缓存服务器。 Apache Traffic Server(ATS) 10.0.0至10.0.5版本和9.0.0至9.2.10版本存在资源管理错误漏洞,该漏洞源于ESI插件未限制最大包含深度可能导致内存消耗过度。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Apache Software Foundation | Apache Traffic Server | 10.0.0 ~ 10.0.5 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2025-32896 | Apache SeaTunnel: Unauthenticated insecure access | |
| CVE-2025-31698 | Apache Traffic Server: Client IP address from PROXY protocol is not used for ACL |
No comments yet