目標達成 すべての支援者に感謝 — 100%達成しました!

目標: 1000 CNY · 調達済み: 1336 CNY

100%

Apache Traffic Server 产品漏洞列表 / CVE 中文分析 102

Apache Traffic Server 产品相关 102 条漏洞,AI 中文标题与摘要、CVSS、POC 一站汇总。

Apache Traffic Server 是由 Apache 软件基金会维护的高性能 HTTP 代理服务器软件。本聚合页收录了该产品中涉及远程代码执行、拒绝服务及权限绕过等高危漏洞,覆盖时间跨度自 2006 年至今。通过整理历史安全公告与补丁信息,读者可快速追踪该厂商的安全响应趋势,深入理解特定架构弱点,并高效检索该版本在过往年份中的具体漏洞记录,为系统加固与升级决策提供数据支持。

ベンダー: Apache Software Foundation

CVE IDタイトルCVSS深刻度公開日
CVE-2026-65100 Apache Traffic Server: HPACK encoder desynchronizes from the decoder after a failed header encode CWE-696 4.8 Medium2026-07-29
CVE-2026-58189 Apache Traffic Server: Plugins resetting the redirect counter enable SSRF amplification CWE-918 7.5 High2026-07-29
CVE-2026-58188 Apache Traffic Server: Memory-safety and limit-bypass errors across experimental plugins CWE-787 8.2 High2026-07-29
CVE-2026-58187 Apache Traffic Server: Multiplexer plugin chunk decoder enables a denial of service CWE-787 3.7 Low2026-07-29
CVE-2026-58186 Apache Traffic Server: webp_transform plugin decodes unsafely and mislabels degraded responses CWE-20 7.5 High2026-07-29
CVE-2026-58185 Apache Traffic Server: Use-after-free in the intercept plugin CWE-416 5.9 Medium2026-07-29
CVE-2026-58184 Apache Traffic Server: header_rewrite plugin cookie handling can corrupt memory CWE-787 8.2 High2026-07-29
CVE-2026-58183 Apache Traffic Server: prefetch plugin can crash on attacker-influenced input CWE-20 5.9 Medium2026-07-29
CVE-2026-58182 Apache Traffic Server: ts_lua plugin has initialization and resource-handling errors CWE-400 8.6 High2026-07-29
CVE-2026-58181 Apache Traffic Server: uri_signing and url_sig plugins can exhaust the stack or crash CWE-121 7.5 High2026-07-29
CVE-2026-58180 Apache Traffic Server: txn_box plugin overflows the stack from attacker input CWE-121 7.5 High2026-07-29
CVE-2026-58179 Apache Traffic Server: regex_remap plugin overflows the stack from attacker input CWE-121 8.1 High2026-07-29
CVE-2026-58178 Apache Traffic Server: ESI plugin allows uncontrolled recursion and server-side request forgery CWE-674 7.5 High2026-07-29
CVE-2026-58177 Apache Traffic Server: Memory-safety and path-traversal errors in the Cripts framework CWE-787 8.1 High2026-07-29
CVE-2026-58175 Apache Traffic Server: HostDB SRV handling leaks memory CWE-401 7.5 High2026-07-29
CVE-2026-58164 Apache Traffic Server: Remap configuration lifetime and TOCTOU errors cause use-after-free CWE-416 7.5 High2026-07-29
CVE-2026-58163 Apache Traffic Server: Cache deserialization and lifetime errors can corrupt state or crash the server CWE-502 7.5 High2026-07-29
CVE-2026-58162 Apache Traffic Server: Certifier plugin trusts client SNI when generating certificates CWE-295 10.0 Critical2026-07-29
CVE-2026-58161 Apache Traffic Server: Memory-safety errors in TLS and SNI handling can crash the server CWE-476 7.5 High2026-07-29
CVE-2026-58160 Apache Traffic Server: Out-of-bounds reads while parsing DNS responses CWE-125 6.5 Medium2026-07-29
CVE-2026-58159 Apache Traffic Server: Listener and ACL handling allow access-control bypass CWE-863 8.2 High2026-07-29
CVE-2026-58158 Apache Traffic Server: PROXY protocol parsing has port truncation and a stack overflow CWE-121 5.9 Medium2026-07-29
CVE-2026-58157 Apache Traffic Server: Improper server-session reuse can expose data across client connections CWE-200 8.7 High2026-07-29
CVE-2026-58156 Apache Traffic Server: URL and port parsing errors allow access-control bypass CWE-863 4.9 Medium2026-07-29
CVE-2026-58155 Apache Traffic Server: Header-name length truncation enables header aliasing and request smuggling CWE-444 9.3 Critical2026-07-29
CVE-2026-58154 Apache Traffic Server: Memory-safety errors in MIME and header parsing CWE-787 8.9 High2026-07-29
CVE-2026-65325 Apache Traffic Server: HTTP/2 multiplexed origin sessions are reused without certificate re-verification CWE-295 4.8 Medium2026-07-29
CVE-2026-65324 Apache Traffic Server: HTTP/2 and HTTP/3 dechunking removes per-stream buffer cap, allowing memory exhaustion CWE-400 7.5 High2026-07-29
CVE-2026-58153 Apache Traffic Server: HTTP/2 to HTTP/1 conversion forwards origin trailers to clients unsafely CWE-444 8.3 High2026-07-29
CVE-2026-58152 Apache Traffic Server: Integer-handling errors in HPACK/XPACK decoding corrupt memory CWE-190 5.9 Medium2026-07-29

Apache Traffic Server 产品累计公开 102 条 CVE 漏洞,本页提供按时间倒序的完整列表,包含 CVSS、CWE、AI 中文摘要与可获取的 POC 链接。