Executive brief
Apache Traffic Server, a high-performance web proxy and caching server, contains a vulnerability in how it processes DNS responses. An attacker could potentially trigger an out-of-bounds memory read, which may lead to service instability or the unintended disclosure of small amounts of memory. Organizations using affected versions should upgrade to the latest patched releases to ensure continued service availability and data protection.
Technical details
An out-of-bounds read vulnerability (CWE-125) exists in Apache Traffic Server's DNS parsing logic. The flaw is triggered when the server processes specially crafted or unexpected DNS answers, leading to memory access beyond the intended buffer. This is a network-reachable vulnerability that does not require authentication or user interaction. Successful exploitation can result in a denial-of-service condition or limited information disclosure. The issue is resolved in versions 9.2.15 and 10.1.4.
Affected products
- Apache Traffic Server 8.0.0 to 8.1.9, 9.0.0 to 9.2.14, 10.0.0 to 10.1.3
Timeline
- 2026-07-29: disclosed
- 2026-07-29: advisory