Resource exhaustion in Apache Traffic Server - CVE-2024-56202
Published: April 14, 2025
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to application unreasonable retain resources when handling the Expect HTTP header field. A remote attacker can send specially crafted HTTP requests to the server, trigger resource exhaustion and perform a denial of service (DoS) attack.
Affected software
Debian Linux
openEuler
trafficserver (Debian package)
trafficserver
trafficserver-debuginfo
trafficserver-debugsource
trafficserver-devel
trafficserver-perl
How to mitigate CVE-2024-56202
trafficserver (Debian package) - update to 9.2.5+ds-0+deb12u2
trafficserver - update to 9.2.5-4
trafficserver-debuginfo - update to 9.2.5-4
trafficserver-debugsource - update to 9.2.5-4
trafficserver-devel - update to 9.2.5-4
trafficserver-perl - update to 9.2.5-4