Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Apache Traffic Server — Vulnerabilities & Security Advisories 102

All 102 CVE vulnerabilities found in Apache Traffic Server, with AI-generated Chinese analysis, references, and POCs.

This page aggregates vulnerability data for the Apache Traffic Server product, focusing on common weakness enumeration classifications and associated security tags. It compiles a comprehensive list of disclosed security flaws, ranging from buffer overflows and authentication bypasses to cross-site scripting and denial-of-service issues affecting this open-source web proxy and caching server. The content spans multiple years, capturing historical advisories as well as recent patches to provide a complete view of the software’s security evolution. Readers can utilize this resource to track vendor advisories from the Apache Software Foundation, gaining insight into the remediation lifecycle and priority of fixes. The page also allows users to understand the specific characteristics of certain weakness classes as they manifest within the context of high-performance traffic management systems. Additionally, individuals can look up the product’s vulnerability history to identify trends in defect introduction and resolution, aiding in risk assessment and compliance verification. By centralizing these details, the page serves as a reference for security analysts, system administrators, and developers who need to evaluate the current security posture of their deployed instances. This approach ensures that stakeholders have access to a structured overview of known issues without needing to sift through numerous disparate announcement channels. The information is presented to facilitate informed decision-making regarding updates, patch management, and architectural security reviews for environments relying on this critical infrastructure software.

Vendor: Apache Software Foundation

CVE IDTitleCVSSSeverityPublished
CVE-2026-65100 Apache Traffic Server: HPACK encoder desynchronizes from the decoder after a failed header encode CWE-696 4.8 Medium2026-07-29
CVE-2026-58189 Apache Traffic Server: Plugins resetting the redirect counter enable SSRF amplification CWE-918 7.5 High2026-07-29
CVE-2026-58188 Apache Traffic Server: Memory-safety and limit-bypass errors across experimental plugins CWE-787 8.2 High2026-07-29
CVE-2026-58187 Apache Traffic Server: Multiplexer plugin chunk decoder enables a denial of service CWE-787 3.7 Low2026-07-29
CVE-2026-58186 Apache Traffic Server: webp_transform plugin decodes unsafely and mislabels degraded responses CWE-20 7.5 High2026-07-29
CVE-2026-58185 Apache Traffic Server: Use-after-free in the intercept plugin CWE-416 5.9 Medium2026-07-29
CVE-2026-58184 Apache Traffic Server: header_rewrite plugin cookie handling can corrupt memory CWE-787 8.2 High2026-07-29
CVE-2026-58183 Apache Traffic Server: prefetch plugin can crash on attacker-influenced input CWE-20 5.9 Medium2026-07-29
CVE-2026-58182 Apache Traffic Server: ts_lua plugin has initialization and resource-handling errors CWE-400 8.6 High2026-07-29
CVE-2026-58181 Apache Traffic Server: uri_signing and url_sig plugins can exhaust the stack or crash CWE-121 7.5 High2026-07-29
CVE-2026-58180 Apache Traffic Server: txn_box plugin overflows the stack from attacker input CWE-121 7.5 High2026-07-29
CVE-2026-58179 Apache Traffic Server: regex_remap plugin overflows the stack from attacker input CWE-121 8.1 High2026-07-29
CVE-2026-58178 Apache Traffic Server: ESI plugin allows uncontrolled recursion and server-side request forgery CWE-674 7.5 High2026-07-29
CVE-2026-58177 Apache Traffic Server: Memory-safety and path-traversal errors in the Cripts framework CWE-787 8.1 High2026-07-29
CVE-2026-58175 Apache Traffic Server: HostDB SRV handling leaks memory CWE-401 7.5 High2026-07-29
CVE-2026-58164 Apache Traffic Server: Remap configuration lifetime and TOCTOU errors cause use-after-free CWE-416 7.5 High2026-07-29
CVE-2026-58163 Apache Traffic Server: Cache deserialization and lifetime errors can corrupt state or crash the server CWE-502 7.5 High2026-07-29
CVE-2026-58162 Apache Traffic Server: Certifier plugin trusts client SNI when generating certificates CWE-295 10.0 Critical2026-07-29
CVE-2026-58161 Apache Traffic Server: Memory-safety errors in TLS and SNI handling can crash the server CWE-476 7.5 High2026-07-29
CVE-2026-58160 Apache Traffic Server: Out-of-bounds reads while parsing DNS responses CWE-125 6.5 Medium2026-07-29
CVE-2026-58159 Apache Traffic Server: Listener and ACL handling allow access-control bypass CWE-863 8.2 High2026-07-29
CVE-2026-58158 Apache Traffic Server: PROXY protocol parsing has port truncation and a stack overflow CWE-121 5.9 Medium2026-07-29
CVE-2026-58157 Apache Traffic Server: Improper server-session reuse can expose data across client connections CWE-200 8.7 High2026-07-29
CVE-2026-58156 Apache Traffic Server: URL and port parsing errors allow access-control bypass CWE-863 4.9 Medium2026-07-29
CVE-2026-58155 Apache Traffic Server: Header-name length truncation enables header aliasing and request smuggling CWE-444 9.3 Critical2026-07-29
CVE-2026-58154 Apache Traffic Server: Memory-safety errors in MIME and header parsing CWE-787 8.9 High2026-07-29
CVE-2026-65325 Apache Traffic Server: HTTP/2 multiplexed origin sessions are reused without certificate re-verification CWE-295 4.8 Medium2026-07-29
CVE-2026-65324 Apache Traffic Server: HTTP/2 and HTTP/3 dechunking removes per-stream buffer cap, allowing memory exhaustion CWE-400 7.5 High2026-07-29
CVE-2026-58153 Apache Traffic Server: HTTP/2 to HTTP/1 conversion forwards origin trailers to clients unsafely CWE-444 8.3 High2026-07-29
CVE-2026-58152 Apache Traffic Server: Integer-handling errors in HPACK/XPACK decoding corrupt memory CWE-190 5.9 Medium2026-07-29

All 102 known CVE vulnerabilities affecting Apache Traffic Server with full Chinese analysis, references, and POCs where available.