| Bug | bullseye | bookworm | sid | Description |
|---|
| CVE-2026-65325 | vulnerable | vulnerable | vulnerable | Apache Traffic Server reuses multiplexed HTTP/2 origin connections wit ... |
| CVE-2026-65324 | vulnerable | vulnerable | vulnerable | Apache Traffic Server drops the per-stream buffer cap when dechunking ... |
| CVE-2026-65100 | vulnerable | vulnerable | vulnerable | Apache Traffic Server updates the HTTP/2 HPACK dynamic table before co ... |
| CVE-2026-59173 | vulnerable (no DSA, postponed) | vulnerable (no DSA, postponed) | vulnerable | Uncontrolled Resource Consumption vulnerability in Apache Traffic Serv ... |
| CVE-2026-58189 | vulnerable | vulnerable | vulnerable | Apache Traffic Server allows redirect-limit bypass when plugins reset ... |
| CVE-2026-58188 | vulnerable | vulnerable | vulnerable | Several Apache Traffic Server experimental plugins have memory-safety ... |
| CVE-2026-58187 | vulnerable | vulnerable | vulnerable | The Apache Traffic Server multiplexer plugin overruns its chunk-decode ... |
| CVE-2026-58186 | vulnerable | vulnerable | vulnerable | The Apache Traffic Server webp_transform plugin can decode unsafely an ... |
| CVE-2026-58185 | vulnerable | vulnerable | vulnerable | The Apache Traffic Server intercept plugin has a use-after-free. This ... |
| CVE-2026-58184 | vulnerable | vulnerable | vulnerable | The Apache Traffic Server header_rewrite plugin can crash or corrupt m ... |
| CVE-2026-58183 | vulnerable | vulnerable | vulnerable | The Apache Traffic Server prefetch plugin can crash when processing at ... |
| CVE-2026-58182 | vulnerable | vulnerable | vulnerable | The Apache Traffic Server ts_lua plugin mishandles initialization, tra ... |
| CVE-2026-58181 | vulnerable | vulnerable | vulnerable | The Apache Traffic Server uri_signing and url_sig plugins can exhaust ... |
| CVE-2026-58180 | vulnerable | vulnerable | vulnerable | The Apache Traffic Server txn_box plugin overflows the stack from atta ... |
| CVE-2026-58179 | vulnerable | vulnerable | vulnerable | The Apache Traffic Server regex_remap plugin overflows the stack and i ... |
| CVE-2026-58178 | vulnerable | vulnerable | vulnerable | The Apache Traffic Server ESI plugin can recurse without bound and fet ... |
| CVE-2026-58177 | vulnerable | vulnerable | vulnerable | The Apache Traffic Server Cripts framework has out-of-bounds writes, p ... |
| CVE-2026-58175 | vulnerable | vulnerable | vulnerable | Apache Traffic Server leaks memory when handling HostDB SRV records. ... |
| CVE-2026-58164 | vulnerable | vulnerable | vulnerable | Apache Traffic Server has use-after-free and time-of-check/time-of-use ... |
| CVE-2026-58163 | vulnerable | vulnerable | vulnerable | Apache Traffic Server mishandles on-disk cache fields and object lifet ... |
| CVE-2026-58162 | vulnerable | vulnerable | vulnerable | The Apache Traffic Server certifier plugin generates certificates base ... |
| CVE-2026-58161 | vulnerable | vulnerable | vulnerable | Apache Traffic Server can crash from null dereferences and dangling re ... |
| CVE-2026-58160 | vulnerable | vulnerable | vulnerable | Apache Traffic Server reads out of bounds while parsing DNS answers. ... |
| CVE-2026-58159 | vulnerable | vulnerable | vulnerable | Apache Traffic Server can bypass IP access controls on UDS listeners a ... |
| CVE-2026-58158 | vulnerable | vulnerable | vulnerable | Apache Traffic Server mishandles PROXY protocol input, truncating port ... |
| CVE-2026-58157 | vulnerable | vulnerable | vulnerable | Apache Traffic Server can reuse server sessions and tunnels improperly ... |
| CVE-2026-58156 | vulnerable | vulnerable | vulnerable | Apache Traffic Server mis-parses ports in URLs and userinfo, allowing ... |
| CVE-2026-58155 | vulnerable | vulnerable | vulnerable | Apache Traffic Server truncates over-long header names, allowing heade ... |
| CVE-2026-58154 | vulnerable | vulnerable | vulnerable | Apache Traffic Server can write out of bounds or overflow integers whi ... |
| CVE-2026-58153 | vulnerable | vulnerable | vulnerable | Apache Traffic Server forwards HTTP/2 origin trailers to HTTP/1 client ... |
| CVE-2026-58152 | vulnerable | vulnerable | vulnerable | Apache Traffic Server mishandles integers while decoding HPACK/XPACK h ... |
| CVE-2026-58151 | vulnerable | vulnerable | vulnerable | Apache Traffic Server can be crashed or driven to resource exhaustion ... |
| CVE-2026-58150 | vulnerable | vulnerable | vulnerable | Apache Traffic Server does not reject Transfer-Encoding in HTTP/2 requ ... |
| CVE-2026-57834 | vulnerable | vulnerable | vulnerable | Apache Traffic Server allows request smuggling if chunked messages are ... |
| CVE-2026-41920 | vulnerable | vulnerable | vulnerable | Improper Access Control vulnerability in Apache Traffic Server. This ... |
| CVE-2026-33930 | vulnerable | vulnerable | vulnerable | Apache Traffic Server copies the client Host header into a fixed-size ... |
| CVE-2026-33267 | vulnerable | vulnerable | vulnerable | Improper Input Validation vulnerability in Apache Traffic Server. Thi ... |
| CVE-2026-24033 | vulnerable | vulnerable | vulnerable | Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response S ... |
| CVE-2026-22068 | vulnerable | vulnerable | vulnerable | Regular Expression without Anchors vulnerability in Apache Traffic Ser ... |
| CVE-2025-65114 | vulnerable | fixed | vulnerable | Apache Traffic Server allows request smuggling if chunked messages are ... |
| CVE-2025-58136 | vulnerable | fixed | vulnerable | A bug in POST request handling causes a crash under a certain conditio ... |
| CVE-2025-49763 | vulnerable | fixed | vulnerable | ESI plugin does not have the limit for maximum inclusion depth, and th ... |
| CVE-2025-31698 | vulnerable | fixed | vulnerable | ACL configured in ip_allow.config or remap.config does not use IP addr ... |
| CVE-2024-56202 | vulnerable | fixed | vulnerable | Expected Behavior Violation vulnerability in Apache Traffic Server. T ... |
| CVE-2024-56195 | vulnerable | fixed | vulnerable | Improper Access Control vulnerability in Apache Traffic Server. This ... |
| CVE-2024-53868 | vulnerable | fixed | vulnerable | Apache Traffic Server allows request smuggling if chunked messages are ... |
| CVE-2024-50306 | fixed | fixed | vulnerable | Unchecked return value can allow Apache Traffic Server to retain privi ... |
| CVE-2024-50305 | vulnerable | fixed | vulnerable | Valid Host header field can cause Apache Traffic Server to crash on so ... |
| CVE-2024-38479 | fixed | fixed | vulnerable | Improper Input Validation vulnerability in Apache Traffic Server. Thi ... |
| CVE-2024-38311 | vulnerable | fixed | vulnerable | Improper Input Validation vulnerability in Apache Traffic Server. Thi ... |
| Bug | Description |
|---|
| CVE-2024-56196 | Improper Access Control vulnerability in Apache Traffic Server. This ... |
| CVE-2024-35296 | Invalid Accept-Encoding header can cause Apache Traffic Server to fail ... |
| CVE-2024-35161 | Apache Traffic Server forwards malformed HTTP chunked trailer section ... |
| CVE-2024-31309 | HTTP/2 CONTINUATIONDoS attack can cause Apache Traffic Server to consu ... |
| CVE-2023-44487 | The HTTP/2 protocol allows a denial of service (server resource consum ... |
| CVE-2023-41752 | Exposure of Sensitive Information to an Unauthorized Actor vulnerabili ... |
| CVE-2023-39456 | Improper Input Validation vulnerability in Apache Traffic Server with ... |
| CVE-2023-38522 | Apache Traffic Server accepts characters that are not allowed for HTTP ... |
| CVE-2023-33934 | Improper Input Validation vulnerability in Apache Software Foundation ... |
| CVE-2023-33933 | Exposure of Sensitive Information to an Unauthorized Actor vulnerabili ... |
| CVE-2023-30631 | Improper Input Validation vulnerability in Apache Software Foundation ... |
| CVE-2022-47185 | Improper input validation vulnerability on the range header in Apache ... |
| CVE-2022-47184 | Exposure of Sensitive Information to an Unauthorized Actor vulnerabili ... |
| CVE-2022-40743 | Improper Input Validation vulnerability for the xdebug plugin in Apach ... |
| CVE-2022-37392 | Improper Check for Unusual or Exceptional Conditions vulnerability in ... |
| CVE-2022-32749 | Improper Check for Unusual or Exceptional Conditions vulnerability han ... |
| CVE-2022-31780 | Improper Input Validation vulnerability in HTTP/2 frame handling of Ap ... |
| CVE-2022-31779 | Improper Input Validation vulnerability in HTTP/2 header parsing of Ap ... |
| CVE-2022-31778 | Improper Input Validation vulnerability in handling the Transfer-Encod ... |
| CVE-2022-28129 | Improper Input Validation vulnerability in HTTP/1.1 header parsing of ... |
| CVE-2022-25763 | Improper Input Validation vulnerability in HTTP/2 request validation o ... |
| CVE-2021-44759 | Improper Authentication vulnerability in TLS origin validation of Apac ... |
| CVE-2021-44040 | Improper Input Validation vulnerability in request line parsing of Apa ... |
| CVE-2021-43082 | Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') ... |
| CVE-2021-41585 | Improper Input Validation vulnerability in accepting socket connection ... |
| CVE-2021-38161 | Improper Authentication vulnerability in TLS origin verification of Ap ... |
| CVE-2021-37150 | Improper Input Validation vulnerability in header parsing of Apache Tr ... |
| CVE-2021-37149 | Improper Input Validation vulnerability in header parsing of Apache Tr ... |
| CVE-2021-37148 | Improper input validation vulnerability in header parsing of Apache Tr ... |
| CVE-2021-37147 | Improper input validation vulnerability in header parsing of Apache Tr ... |
| CVE-2021-35474 | Stack-based Buffer Overflow vulnerability in cachekey plugin of Apache ... |
| CVE-2021-32567 | Improper Input Validation vulnerability in HTTP/2 of Apache Traffic Se ... |
| CVE-2021-32566 | Improper Input Validation vulnerability in HTTP/2 of Apache Traffic Se ... |
| CVE-2021-32565 | Invalid values in the Content-Length header sent to Apache Traffic Ser ... |
| CVE-2021-27737 | Apache Traffic Server 9.0.0 is vulnerable to a remote DOS attack on th ... |
| CVE-2021-27577 | Incorrect handling of url fragment vulnerability of Apache Traffic Ser ... |
| CVE-2020-17509 | ATS negative cache option is vulnerable to a cache poisoning attack. I ... |
| CVE-2020-17508 | The ATS ESI plugin has a memory disclosure vulnerability. If you are r ... |
| CVE-2020-9494 | Apache Traffic Server 6.0.0 to 6.2.3, 7.0.0 to 7.1.10, and 8.0.0 to 8. ... |
| CVE-2020-9481 | Apache ATS 6.0.0 to 6.2.3, 7.0.0 to 7.1.9, and 8.0.0 to 8.0.6 is vulne ... |
| CVE-2020-1944 | There is a vulnerability in Apache Traffic Server 6.0.0 to 6.2.3, 7.0. ... |
| CVE-2019-17565 | There is a vulnerability in Apache Traffic Server 6.0.0 to 6.2.3, 7.0. ... |
| CVE-2019-17559 | There is a vulnerability in Apache Traffic Server 6.0.0 to 6.2.3, 7.0. ... |
| CVE-2019-10079 | Apache Traffic Server is vulnerable to HTTP/2 setting flood attacks. E ... |
| CVE-2019-9518 | Some HTTP/2 implementations are vulnerable to a flood of empty frames, ... |
| CVE-2019-9515 | Some HTTP/2 implementations are vulnerable to a settings flood, potent ... |
| CVE-2019-9514 | Some HTTP/2 implementations are vulnerable to a reset flood, potential ... |
| CVE-2019-9512 | Some HTTP/2 implementations are vulnerable to ping floods, potentially ... |
| CVE-2018-11783 | sslheaders plugin extracts information from the client certificate and ... |
| CVE-2018-8040 | Pages that are rendered using the ESI plugin can have access to the co ... |
| CVE-2018-8022 | A carefully crafted invalid TLS handshake can cause Apache Traffic Ser ... |
| CVE-2018-8005 | When there are multiple ranges in a range request, Apache Traffic Serv ... |
| CVE-2018-8004 | There are multiple HTTP smuggling and cache poisoning issues when clie ... |
| CVE-2018-1318 | Adding method ACLs in remap.config can cause a segfault when the user ... |
| CVE-2017-7671 | There is a DOS attack vulnerability in Apache Traffic Server (ATS) 5.2 ... |
| CVE-2017-5660 | There is a vulnerability in Apache Traffic Server (ATS) 6.2.0 and prio ... |
| CVE-2017-5659 | Apache Traffic Server before 6.2.1 generates a coredump when there is ... |
| CVE-2016-5396 | Apache Traffic Server 6.0.0 to 6.2.0 are affected by an HPACK Bomb Att ... |
| CVE-2015-5206 | Unspecified vulnerability in the HTTP/2 experimental feature in Apache ... |
| CVE-2015-5168 | Unspecified vulnerability in the HTTP/2 experimental feature in Apache ... |
| CVE-2015-3249 | The HTTP/2 experimental feature in Apache Traffic Server 5.3.x before ... |
| CVE-2014-10022 | Apache Traffic Server before 5.1.2 allows remote attackers to cause a ... |
| CVE-2014-3624 | Apache Traffic Server 5.1.x before 5.1.1 allows remote attackers to by ... |
| CVE-2014-3525 | Unspecified vulnerability in Apache Traffic Server 3.x through 3.2.5, ... |
| CVE-2012-0256 | Apache Traffic Server 2.0.x and 3.0.x before 3.0.4 and 3.1.x before 3. ... |
| CVE-2010-2952 | Apache Traffic Server before 2.0.1, and 2.1.x before 2.1.2-unstable, d ... |