Executive brief
Apache Traffic Server, a high-performance caching proxy used to manage web traffic, contains a flaw in how it handles data sent between different web protocols. When converting modern HTTP/2 traffic to older HTTP/1 format, the server fails to properly format certain data trailers, which can lead to request smuggling. This could allow an attacker to bypass security controls, interfere with user sessions, or gain unauthorized access to data.
Technical details
A vulnerability classified as HTTP Request/Response Smuggling (CWE-444) exists in Apache Traffic Server. The issue occurs during the protocol translation process where HTTP/2 origin trailers are forwarded to HTTP/1 clients without the necessary chunked framing required for the HTTP/1 protocol. This inconsistency in message framing allows a remote, unauthenticated attacker to desynchronize the proxy's interpretation of the message stream. This can be exploited to bypass security filters or poison web caches. The issue is fixed in versions 9.2.15 and 10.1.4.
Affected products
- Apache Traffic Server 10.0.0 through 10.1.3
Timeline
- 2026-07-29: disclosed
- 2026-07-29: advisory