Apache traffic server是美国Apache基金会开源的一个高性能HTTP代理服务器。 Apache Traffic Server 8.0.0版本至8.1.9版本、9.0.0版本至9.2.14版本和10.0.0版本至10.1.3版本存在缓冲区错误漏洞,该漏洞源于在重定向处理期间将客户端Host标头复制到固定大小栈缓冲区时缺乏边界检查,导致超长Host标头溢出栈。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Apache Software Foundation | Apache Traffic Server | 8.0.0≤ 8.1.9 |
affected |
9.0.0≤ 9.2.14 |
affected | ||
10.0.0≤ 10.1.3 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Apache Software Foundation | Apache Traffic Server | 8.0.0 ~ 8.1.9 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-33267 | 10.0 CRITICAL | Apache Traffic Server: Untrusted @ headers can spoof ATS internal metadata |
| CVE-2026-57834 | 10.0 CRITICAL | Apache Traffic Server: Malformed chunked message body allows request smuggling |
| CVE-2026-58150 | 10.0 CRITICAL | Apache Traffic Server: HTTP/2 requests with Transfer-Encoding are not rejected, allowing r |
| CVE-2026-58162 | 10.0 CRITICAL | Apache Traffic Server: Certifier plugin trusts client SNI when generating certificates |
| CVE-2026-41920 | 9.3 CRITICAL | Apache Traffic Server: SNI to Host header matching policy is not properly enforced |
| CVE-2026-58155 | 9.3 CRITICAL | Apache Traffic Server: Header-name length truncation enables header aliasing and request s |
| CVE-2026-58154 | 8.9 HIGH | Apache Traffic Server: Memory-safety errors in MIME and header parsing |
| CVE-2026-58157 | 8.7 HIGH | Apache Traffic Server: Improper server-session reuse can expose data across client connect |
| CVE-2026-58182 | 8.6 HIGH | Apache Traffic Server: ts_lua plugin has initialization and resource-handling errors |
| CVE-2026-58153 | 8.3 HIGH | Apache Traffic Server: HTTP/2 to HTTP/1 conversion forwards origin trailers to clients uns |
| CVE-2026-22068 | 8.2 HIGH | Apache Traffic Server: Regex mappings match with malicious domain names |
| CVE-2026-58188 | 8.2 HIGH | Apache Traffic Server: Memory-safety and limit-bypass errors across experimental plugins |
| CVE-2026-58184 | 8.2 HIGH | Apache Traffic Server: header_rewrite plugin cookie handling can corrupt memory |
| CVE-2026-58159 | 8.2 HIGH | Apache Traffic Server: Listener and ACL handling allow access-control bypass |
| CVE-2026-58179 | 8.1 HIGH | Apache Traffic Server: regex_remap plugin overflows the stack from attacker input |
| CVE-2026-58177 | 8.1 HIGH | Apache Traffic Server: Memory-safety and path-traversal errors in the Cripts framework |
| CVE-2026-58164 | 7.5 HIGH | Apache Traffic Server: Remap configuration lifetime and TOCTOU errors cause use-after-free |
| CVE-2026-58151 | 7.5 HIGH | Apache Traffic Server: Abusive HTTP/2 framing can exhaust resources and crash the server |
| CVE-2026-58181 | 7.5 HIGH | Apache Traffic Server: uri_signing and url_sig plugins can exhaust the stack or crash |
| CVE-2026-58180 | 7.5 HIGH | Apache Traffic Server: txn_box plugin overflows the stack from attacker input |
Showing top 20 of 41 CVEs. View all on vendor page → →
No comments yet