Executive brief
Apache Traffic Server, a high-performance caching proxy used to manage web traffic, contains a vulnerability in how it handles specific network connection data. An attacker could exploit this flaw to cause the server to crash, leading to a denial of service for users and applications relying on the proxy. Organizations should update to the latest versions to ensure service availability and stability.
Technical details
A stack-based buffer overflow (CWE-121) exists in Apache Traffic Server due to improper handling of PROXY protocol input. The vulnerability occurs when the server processes malformed PROXY protocol headers, leading to port truncation and a stack overflow. This is a network-based attack that does not require authentication, though the CVSS vector suggests high complexity (AC:H), likely due to specific configuration requirements or timing. Successful exploitation primarily impacts service availability by causing a crash (Denial of Service). The issue is resolved in versions 9.2.15 and 10.1.4.
Affected products
- Apache Traffic Server 8.0.0 through 8.1.9, 9.0.0 through 9.2.14, 10.0.0 through 10.1.3
Timeline
- 2026-07-29: disclosed
- 2026-07-29: advisory
- 2026-07-29: patched