Junglewise Threat Intelligence

CVE-2025-65114: Apache Traffic Server request smuggling in chunked messages

CVE-2025-65114 · Severity: high · CVSS 7.5 · Published 2026-04-02

Technologies: Apache Traffic Server. Vendors: Apache.

Executive brief

Apache Traffic Server, a high-performance caching proxy used to manage and speed up web traffic, is vulnerable to a request smuggling flaw. By sending specially crafted malformed messages, an attacker can bypass security controls or interfere with other users' web requests. This could lead to unauthorized access to internal systems or the delivery of incorrect content to users.

Technical details

A request smuggling vulnerability (CWE-444) exists in Apache Traffic Server due to the inconsistent interpretation of malformed HTTP chunked messages. An unauthenticated remote attacker can exploit this by sending a crafted request that is interpreted differently by the proxy and the backend server. This allows the attacker to 'smuggle' a hidden request inside a legitimate one, potentially bypassing security filters or poisoning the web cache. The issue is resolved in versions 9.2.13 and 10.1.2.

Affected products

  • Apache Traffic Server 9.0.0 through 9.2.12, 10.0.0 through 10.1.1

Timeline

  • 2026-04-02: advisory: Initial advisory published by Apache Software Foundation
  • 2026-04-02: disclosed: CVE-2025-65114 published to NVD

References

Related threats