Apache Software Foundation traffic server Vulnerabilities
CVE security advisories and vulnerability history for traffic server by Apache Software Foundation.
Last updated
Overview
Apache Software Foundation traffic server has 81 published CVE records since 2010, of which 1 are in CISA's Known Exploited Vulnerabilities catalog and 1 have a known public exploit. The average CVSS base score across scored CVEs is 7.6.
This page aggregates every publicly disclosed vulnerability (CVE) affecting Apache Software Foundation traffic server, with a severity breakdown, the affected and patched versions, the most common weakness types, and the full CVE list.
Severity and exploitation
How the CVSS severity of Apache Software Foundation traffic server's CVEs breaks down, plus how many are exploited in the wild or have public exploit code.
In CISA’s Known Exploited Vulnerabilities catalog
1
One of Apache Software Foundation traffic server's CVEs is confirmed exploited in the wild.
Public exploits
1
One of Apache Software Foundation traffic server's CVEs has a known public exploit available.
Affected versions and CVEs
Browse every Apache Software Foundation traffic server version named in a CVE, then pick one to see only the CVEs that affect it.
Version ranges
- 6.0.0 <= v <= 6.2.316 CVEs
- 7.0.0 <= v <= 7.1.68 CVEs
- 8.0.0 <= v <= 8.0.38 CVEs
- 9.0.0 <= v <= 9.0.16 CVEs
- 6.0.0 <= v <= 6.2.25 CVEs
- 7.0.0 <= v <= 7.1.125 CVEs
- 8.0.0 <= v <= 8.1.15 CVEs
- 8.0.0 <= v <= 8.1.25 CVEs
- 8.0.0 <= v <= 8.1.45 CVEs
- 9.0.0 <= v <= 9.1.25 CVEs
- 10.0.0 <= v < 10.0.44 CVEs
- 7.0.0 <= v <= 7.1.34 CVEs
- 9.0.0 <= v <= 9.1.04 CVEs
- 5.3.0 <= v <= 5.3.03 CVEs
- 7.0.0 <= v <= 7.1.83 CVEs
- 8.0.0 <= v < 8.1.113 CVEs
- 8.0.0 <= v < 8.1.73 CVEs
- 8.0.0 <= v <= 8.0.53 CVEs
- 9.0.0 <= v < 9.2.13 CVEs
- 9.0.0 <= v < 9.2.33 CVEs
- 9.0.0 <= v < 9.2.53 CVEs
- 9.0.0 <= v < 9.2.63 CVEs
- 9.0.0 <= v < 9.2.93 CVEs
- <= 6.2.02 CVEs
- 10.0.0 <= v < 10.0.62 CVEs
- 10.0.0 <= v < 10.1.22 CVEs
- 2.1.0 <= v <= 2.1.02 CVEs
- 2.1.1 <= v <= 2.1.12 CVEs
- 5.3.1 <= v <= 5.3.12 CVEs
- 7.0.0 <= v <= 7.0.02 CVEs
- 7.0.0 <= v <= 7.1.102 CVEs
- 8.0.0 <= v < 8.1.62 CVEs
- 8.0.0 <= v < 8.1.92 CVEs
- 8.0.0 <= v <= 8.0.72 CVEs
- 8.0.0 <= v <= 8.1.02 CVEs
- 8.0.0 <= v <= 8.1.102 CVEs
- 8.0.0 <= v <= 8.1.62 CVEs
- 8.0.0 <= v <= 8.1.72 CVEs
- 9.0.0 <= v < 9.1.42 CVEs
- 9.0.0 <= v < 9.2.112 CVEs
- 9.0.0 <= v < 9.2.132 CVEs
- 9.0.0 <= v <= 9.2.02 CVEs
- 9.0.0 <= v <= 9.2.12 CVEs
- 9.0.0 <= v <= 9.2.42 CVEs
- < 7.1.71 CVE
- <= 2.0.01 CVE
- <= 5.1.11 CVE
- <= 9.2.21 CVE
- 10.0.0 <= v < 10.0.21 CVE
- 10.0.0 <= v < 10.0.51 CVE
- 2.0.0 <= v <= 2.0.01 CVE
- 2.0.1 <= v <= 2.0.11 CVE
- 2.1.2 <= v <= 2.1.21 CVE
- 2.1.3 <= v <= 2.1.31 CVE
- 2.1.4 <= v <= 2.1.41 CVE
- 2.1.5 <= v <= 2.1.51 CVE
- 2.1.6 <= v <= 2.1.61 CVE
- 2.1.7 <= v <= 2.1.71 CVE
- 2.1.8 <= v <= 2.1.81 CVE
- 2.1.9 <= v <= 2.1.91 CVE
- 3.0.0 <= v <= 3.0.01 CVE
- 3.0.1 <= v <= 3.0.11 CVE
- 3.0.2 <= v <= 3.0.21 CVE
- 3.0.3 <= v <= 3.0.31 CVE
- 3.0.4 <= v <= 3.0.41 CVE
- 3.1.0 <= v <= 3.1.01 CVE
- 3.1.1 <= v <= 3.1.11 CVE
- 3.1.2 <= v <= 3.1.21 CVE
- 3.1.3 <= v <= 3.1.31 CVE
- 3.1.4 <= v <= 3.1.41 CVE
- 3.2.0 <= v <= 3.2.01 CVE
- 3.3.0 <= v <= 3.3.01 CVE
- 3.3.1 <= v <= 3.3.11 CVE
- 3.3.2 <= v <= 3.3.21 CVE
- 3.3.3 <= v <= 3.3.31 CVE
- 3.3.4 <= v <= 3.3.41 CVE
- 3.3.5 <= v <= 3.3.51 CVE
- 4.0.1 <= v <= 4.0.11 CVE
- 4.1.0 <= v <= 4.1.01 CVE
- 4.2.0 <= v <= 4.2.01 CVE
- 4.2.1 <= v <= 4.2.11 CVE
- 5.0.0 <= v <= 5.0.01 CVE
- 5.1.0 <= v <= 5.1.01 CVE
- 5.2.0 <= v <= 5.3.21 CVE
- 6.0.0 <= v <= 6.0.01 CVE
- 6.0.0 <= v <= 6.0.31 CVE
- 6.0.0 <= v <= 6.2.01 CVE
- 6.1.0 <= v <= 6.1.01 CVE
- 6.1.1 <= v <= 6.1.11 CVE
- 6.2.0 <= v <= 6.2.01 CVE
- 6.2.1 <= v <= 6.2.11 CVE
- 6.2.2 <= v <= 6.2.21 CVE
- 7.0.0 <= v < 7.1.101 CVE
- 7.0.0 <= v <= 7.1.111 CVE
- 7.0.0 <= v <= 7.1.51 CVE
- 7.0.0 <= v <= 7.1.91 CVE
- 8.0.0 <= v < 8.0.41 CVE
- 8.0.0 <= v < 8.0.71 CVE
- 8.0.0 <= v < 8.1.101 CVE
- 8.0.0 <= v < 8.1.51 CVE
- 8.0.0 <= v <= 8.0.11 CVE
- 8.0.0 <= v <= 8.0.61 CVE
- 8.0.0 <= v <= 8.0.81 CVE
- 8.0.0 <= v <= 8.1.111 CVE
- 8.0.0 <= v <= 8.1.31 CVE
- 8.0.0 <= v <= 8.1.51 CVE
- 8.0.0 <= v <= 8.1.91 CVE
- 9.0.0 <= v < 9.1.31 CVE
- 9.0.0 <= v < 9.2.101 CVE
- 9.0.0 <= v < 9.2.41 CVE
- 9.0.0 <= v <= 9.0.01 CVE
- 9.0.0 <= v <= 9.1.11 CVE
- 9.0.0 <= v <= 9.1.31 CVE
- 9.0.0 <= v <= 9.2.31 CVE
Fixed in
- 10.0.44 CVEs
- 8.1.113 CVEs
- 8.1.73 CVEs
- 9.2.13 CVEs
- 9.2.33 CVEs
- 9.2.53 CVEs
- 9.2.63 CVEs
- 9.2.93 CVEs
- > 8.1.102 CVEs
- > 8.1.62 CVEs
- > 8.1.72 CVEs
- > 9.2.02 CVEs
- > 9.2.12 CVEs
- > 9.2.42 CVEs
- 10.0.62 CVEs
- 10.1.22 CVEs
- 8.1.62 CVEs
- 8.1.92 CVEs
- 9.1.42 CVEs
- 9.2.112 CVEs
- 9.2.132 CVEs
- > 8.1.91 CVE
- > 9.2.21 CVE
- > 9.2.31 CVE
- 10.0.21 CVE
- 10.0.51 CVE
- 7.1.101 CVE
- 7.1.71 CVE
- 8.0.41 CVE
- 8.0.71 CVE
- 8.1.101 CVE
- 8.1.51 CVE
- 9.1.31 CVE
- 9.2.101 CVE
- 9.2.41 CVE
81 CVEs
- High · CVSS 7.5EPSS 0.4% (35th pct)2026-04-02
- High · CVSS 7.5EPSS 0.7% (48th pct)2026-04-02
- High · CVSS 7.5EPSS 0.4% (36th pct)2025-06-19
- High · CVSS 7.5EPSS 0.6% (46th pct)2025-06-19
- High · CVSS 7.5EPSS 0.6% (46th pct)2025-04-03
- Medium · CVSS 6.3EPSS 0.8% (54th pct)2025-03-06
- Medium · CVSS 6.3EPSS 0.7% (50th pct)2025-03-06
- Medium · CVSS 6.3EPSS 0.7% (50th pct)2025-03-06
- Medium · CVSS 4.3EPSS 0.8% (53th pct)2025-03-06
- Medium · CVSS 6.5EPSS 0.1% (4th pct)2024-11-20
- Critical · CVSS 9.1EPSS 1.6% (73th pct)2024-11-14
- High · CVSS 7.5EPSS 0.9% (57th pct)2024-11-14
- High · CVSS 7.5EPSS 0.9% (57th pct)2024-11-14
- High · CVSS 7.5EPSS 1.0% (58th pct)2024-07-26
- High · CVSS 8.2EPSS 1.1% (61th pct)2024-07-26
- Critical · CVSS 9.1EPSS 1.0% (58th pct)2024-07-26
- High · CVSS 7.5EPSS 94.6% (100th pct)2024-04-10
- High · CVSS 7.5EPSS 53.5% (99th pct)2023-10-17
- High · CVSS 7.5EPSS 1.2% (65th pct)2023-10-17
- High vulnerability · 2023-10-10
Added to CISA KEV 2023-10-10
High · CVSS 7.5EPSS 100.0% (100th pct)2023-10-10 - Critical · CVSS 9.1EPSS 1.1% (61th pct)2023-08-09
- High · CVSS 7.5EPSS 1.5% (71th pct)2023-08-09
- High · CVSS 7.5EPSS 2.0% (78th pct)2023-06-14
- High · CVSS 7.5EPSS 1.5% (71th pct)2023-06-14
- High · CVSS 7.5EPSS 1.9% (77th pct)2023-06-14
- Medium · CVSS 6.1EPSS 1.1% (61th pct)2022-12-19
- Medium · CVSS 5.3EPSS 1.1% (62th pct)2022-12-19
- High · CVSS 7.5EPSS 1.3% (67th pct)2022-12-19
- High · CVSS 7.5EPSS 1.9% (77th pct)2022-08-10
- High · CVSS 7.5EPSS 1.6% (73th pct)2022-08-10
Showing 30 of 81
Common weakness types
The CWE weakness categories most often found in Apache Software Foundation traffic server CVEs. Follow any weakness for its full explanation.
- CWE-20Improper Input Validation18 CVEs
- CWE-400Uncontrolled Resource Consumption10 CVEs
- CWE-444Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')9 CVEs
- CWE-200Exposure of Sensitive Information to an Unauthorized Actor3 CVEs
- CWE-284Improper Access Control3 CVEs
- CWE-287Improper Authentication2 CVEs
- CWE-754Improper Check for Unusual or Exceptional Conditions2 CVEs
- CWE-79Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')1 CVE
Disclosure activity by year
How many Apache Software Foundation traffic server CVEs were published each year.
Other Apache Software Foundation products
Browse vulnerabilities for other products by Apache Software Foundation.
Frequently asked questions
Common questions about Apache Software Foundation traffic server vulnerabilities.
- How many CVEs does Apache Software Foundation traffic server have?
- Apache Software Foundation traffic server has 81 published CVE records since 2010.
- How many Apache Software Foundation traffic server CVEs are in CISA KEV?
- Yes — 1 of Apache Software Foundation traffic server's CVEs are listed in CISA's Known Exploited Vulnerabilities catalog, confirmed exploited in the wild and carrying a CISA remediation deadline.
- Are there public exploits for Apache Software Foundation traffic server vulnerabilities?
- Yes — 1 of Apache Software Foundation traffic server's CVEs have a known public exploit.
- Which versions of Apache Software Foundation traffic server are affected?
- 149 distinct Apache Software Foundation traffic server versions are named across its CVEs. Use the version filter above to see the CVEs affecting a specific version.
- What are the most common weakness types in Apache Software Foundation traffic server CVEs?
- Apache Software Foundation traffic server's CVEs most often map to these CWE weakness types: CWE-20 (Improper Input Validation), CWE-400 (Uncontrolled Resource Consumption), CWE-444 (Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')), CWE-200 (Exposure of Sensitive Information to an Unauthorized Actor).
- How many critical Apache Software Foundation traffic server vulnerabilities are there?
- Apache Software Foundation traffic server has 13 critical and 55 high-severity CVEs.
- What is the average severity of Apache Software Foundation traffic server CVEs?
- The average CVSS base score across Apache Software Foundation traffic server's scored CVEs is 7.6.
References
- All Apache Software Foundation vulnerabilities
- The MITRE CVE Program (opens in a new tab)
- Learn: What is a CVE?
- CWE directory: the weakness types these CVEs map to
Vulnerability data is sourced from the CVE Program; severity, KEV, and exploit signals are aggregated by RadicalNotion.AI.
Track Apache Software Foundation traffic server vulnerabilities
Monitor new Apache Software Foundation traffic server vulnerabilities as they are disclosed, with AI-written analysis and remediation guidance.