Executive brief
Apache Traffic Server, a high-performance caching proxy used to manage web traffic, contains a flaw that improperly reuses internal communication channels between different users. This could allow one user to inadvertently access or intercept data belonging to another user's session. Organizations using affected versions should upgrade to the latest patched releases to prevent potential data exposure and maintain user privacy.
Technical details
Apache Traffic Server is vulnerable to information exposure (CWE-200) due to the improper reuse of server sessions and tunnels. The flaw allows data from one client connection to be exposed to another when the proxy incorrectly recycles backend connections. This is a network-based attack that does not require authentication, though it may require specific timing or high-concurrency conditions (reflected in the High Attack Complexity). The issue affects versions 8.x, 9.x, and 10.x, and has been addressed in versions 9.2.15 and 10.1.4.
Affected products
- Apache Traffic Server 8.0.0 through 8.1.9, 9.0.0 through 9.2.14, 10.0.0 through 10.1.3
Timeline
- 2026-07-29: disclosed
- 2026-07-29: advisory