Executive brief
Apache Traffic Server, a high-performance caching proxy used to speed up web content delivery, contains a flaw in how it manages stored data. An attacker could exploit this to corrupt the server's internal state or cause the service to crash. This could lead to service outages or the delivery of incorrect data to users, impacting business operations and reliability.
Technical details
Apache Traffic Server is vulnerable to a state corruption issue due to the improper handling of on-disk cache fields and object lifetimes. The vulnerability is classified as a deserialization of untrusted data (CWE-502) within the caching component. An unauthenticated remote attacker can exploit this flaw to corrupt the cache state or trigger a denial-of-service (DoS) condition by crashing the server. The issue affects versions 8.x, 9.x, and 10.x, and has been addressed in versions 9.2.15 and 10.1.4.
Affected products
- Apache Traffic Server 8.0.0 through 8.1.9, 9.0.0 through 9.2.14, 10.0.0 through 10.1.3
Timeline
- 2026-07-29: disclosed
- 2026-07-29: advisory
- 2026-07-29: patched