Apache Software Foundation trafficserver Vulnerabilities
CVE security advisories and vulnerability history for trafficserver by Apache Software Foundation.
74
Total CVEs
Published
1
In CISA KEV
Exploited in the wild
2
Public exploits
PoC or exploit code
7.5
Avg CVSS
2017–2026
Last updated
Overview
Apache Software Foundation trafficserver has 74 published CVE records since 2017, of which 1 are in CISA's Known Exploited Vulnerabilities catalog and 2 have a known public exploit. The average CVSS base score across scored CVEs is 7.5.
This page aggregates every publicly disclosed vulnerability (CVE) affecting Apache Software Foundation trafficserver, with a severity breakdown, the affected and patched versions, the most common weakness types, and the full CVE list.
Severity and exploitation
How the CVSS severity of Apache Software Foundation trafficserver's CVEs breaks down, plus how many are exploited in the wild or have public exploit code.
Critical8
High54
Medium12
Low0
In CISA’s Known Exploited Vulnerabilities catalog
1
One of Apache Software Foundation trafficserver's CVEs is confirmed exploited in the wild.
Public exploits
2
2 of Apache Software Foundation trafficserver's CVEs have a known public exploit available.
Affected versions and CVEs
Browse every Apache Software Foundation trafficserver version named in a CVE, then pick one to see only the CVEs that affect it.
Common questions about Apache Software Foundation trafficserver vulnerabilities.
How many CVEs does Apache Software Foundation trafficserver have?
Apache Software Foundation trafficserver has 74 published CVE records since 2017.
How many Apache Software Foundation trafficserver CVEs are in CISA KEV?
Yes — 1 of Apache Software Foundation trafficserver's CVEs are listed in CISA's Known Exploited Vulnerabilities catalog, confirmed exploited in the wild and carrying a CISA remediation deadline.
Are there public exploits for Apache Software Foundation trafficserver vulnerabilities?
Yes — 2 of Apache Software Foundation trafficserver's CVEs have a known public exploit.
Which versions of Apache Software Foundation trafficserver are affected?
520 distinct Apache Software Foundation trafficserver versions are named across its CVEs. Use the version filter above to see the CVEs affecting a specific version.
What are the most common weakness types in Apache Software Foundation trafficserver CVEs?
Apache Software Foundation trafficserver's CVEs most often map to these CWE weakness types: CWE-20 (Improper Input Validation), CWE-400 (Uncontrolled Resource Consumption), CWE-444 (Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')), CWE-200 (Exposure of Sensitive Information to an Unauthorized Actor).
How many critical Apache Software Foundation trafficserver vulnerabilities are there?
Apache Software Foundation trafficserver has 8 critical and 54 high-severity CVEs.
What is the average severity of Apache Software Foundation trafficserver CVEs?
The average CVSS base score across Apache Software Foundation trafficserver's scored CVEs is 7.5.