Known vulnerabilities in Apache Traffic Server

Software CPE: cpe:2.3:a:apache_foundation:apache_ats:*:*:*:*:*:*:*:*
Total vulnerabilities: 96
Public exploits: 0
Known exploited (KEV): 0
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting Apache Traffic Server Apache Traffic Server is affected by 96 known vulnerabilities: 19 high, 70 medium, 7 low Critical High Medium Low

Vulnerabilities (96)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU145206 - Resource exhaustion
CVE-2026-59173
CWE-400 Medium
No
No
9.2.14, 10.1.3 25.08.2026 SB20260824137
SB2026082580
SB2026082581
and 5 more
#VU144899 - Resource exhaustion
CVE-2026-65324
CWE-400 Medium
No
No
9.2.15, 10.1.4 24.08.2026 SB20260824179
SB20260824184
SB20260824185
and 5 more
#VU144900 - Stack-based buffer overflow
CVE-2026-33930
CWE-121 Medium
No
No
9.2.15, 10.1.4 24.08.2026 SB20260824179
SB20260824184
SB20260824185
and 5 more
#VU144901 - Improper control of a resource through its lifetime
CVE-2026-65100
CWE-664 Medium
No
No
9.2.15, 10.1.4 24.08.2026 SB20260824179
SB20260824184
SB20260824185
and 5 more
#VU144902 - Improper Certificate Validation
CVE-2026-65325
CWE-295 High
No
No
9.2.15, 10.1.4 24.08.2026 SB20260824179
SB20260824184
SB20260824185
and 5 more
#VU144760 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling')
CVE-2026-33267
CWE-444 High
No
No
9.2.14, 10.1.3 24.08.2026 SB20260824137
SB20260824184
SB20260824185
and 5 more
#VU144761 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling')
CVE-2026-58150
CWE-444 High
No
No
9.2.14, 10.1.3 24.08.2026 SB20260824137
SB20260824184
SB20260824185
and 5 more
#VU144762 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling')
CVE-2026-58155
CWE-444 High
No
No
9.2.14, 10.1.3 24.08.2026 SB20260824137
SB20260824184
SB20260824185
and 5 more
#VU144763 - Out-of-bounds write
CVE-2026-58154
CWE-787 High
No
No
9.2.14, 10.1.3 24.08.2026 SB20260824137
SB20260824184
SB20260824185
and 5 more
#VU144764 - Session Fixation
CVE-2026-58157
CWE-384 Medium
No
No
9.2.14, 10.1.3 24.08.2026 SB20260824137
SB20260824184
SB20260824185
and 7 more
#VU144765 - Permissive Regular Expression
CVE-2026-22068
CWE-625 High
No
No
9.2.14, 10.1.3 24.08.2026 SB20260824137
SB20260824184
SB20260824185
and 6 more
#VU144766 - Out-of-bounds write
CVE-2026-58177
CWE-787 High
No
No
9.2.14, 10.1.3 24.08.2026 SB20260824137
SB20260824184
SB20260824185
and 2 more
#VU144767 - Resource exhaustion
CVE-2026-58151
CWE-400 Medium
No
No
9.2.14, 10.1.3 24.08.2026 SB20260824137
SB20260824184
SB20260824185
and 5 more
#VU144768 - NULL Pointer Dereference
CVE-2026-58161
CWE-476 Medium
No
No
9.2.14, 10.1.3 24.08.2026 SB20260824137
SB20260824184
SB20260824185
and 7 more
#VU144769 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling')
CVE-2026-57834
CWE-444 High
No
No
9.2.14, 10.1.3 24.08.2026 SB20260824137
SB20260824184
SB20260824185
and 5 more
#VU144770 - Authentication Bypass by Spoofing
CVE-2026-58162
CWE-290 High
No
No
9.2.14, 10.1.3 24.08.2026 SB20260824137
SB20260824184
SB20260824185
and 5 more
#VU144771 - Incorrect Comparison
CVE-2026-41920
CWE-697 High
No
No
9.2.14, 10.1.3 24.08.2026 SB20260824137
SB20260824184
SB20260824185
and 5 more
#VU144772 - Improper Initialization
CVE-2026-58182
CWE-665 Medium
No
No
9.2.14, 10.1.3 24.08.2026 SB20260824137
SB20260824184
SB20260824185
and 7 more
#VU144773 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling')
CVE-2026-58153
CWE-444 High
No
No
9.2.14, 10.1.3 24.08.2026 SB20260824137
SB20260824184
SB20260824185
and 5 more
#VU144774 - Improper Access Control
CVE-2026-58159
CWE-284 Medium
No
No
9.2.14, 10.1.3 24.08.2026 SB20260824137
SB20260824184
SB20260824185
and 5 more


Showing elements 1 - 20 out of 96