Executive brief
Apache Traffic Server, a high-performance caching proxy used to speed up web content delivery, contains a vulnerability in its image transformation plugin. An attacker could exploit this to cause the system to process images unsafely and serve incorrect, cached data. This primarily impacts the availability and reliability of the web services being accelerated by the proxy.
Technical details
A vulnerability exists in the webp_transform plugin of Apache Traffic Server due to improper input validation (CWE-20) during image decoding. The plugin may decode data unsafely and subsequently serve mislabeled responses that are stored in the cache. This is a network-reachable vulnerability that requires no authentication or user interaction. The primary impact is on service availability (Denial of Service), as indicated by the CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H vector. Users are advised to upgrade to versions 9.2.15 or 10.1.4 to resolve the issue.
Affected products
- Apache Traffic Server 8.0.0 through 8.1.9, 9.0.0 through 9.2.14, 10.0.0 through 10.1.3
Timeline
- 2026-07-29: disclosed
- 2026-07-29: advisory