Executive brief
Apache Traffic Server, a high-performance caching proxy used to manage web traffic, contains a vulnerability in its multiplexer plugin. An attacker can send specific data that causes the software to crash or become unresponsive. This could lead to a temporary disruption of web services and content delivery for organizations using the affected versions.
Technical details
An out-of-bounds write vulnerability (CWE-787) exists in the multiplexer plugin of Apache Traffic Server. The flaw is triggered when the plugin processes upstream input, leading to a buffer overrun during chunk-decoding operations. A remote, unauthenticated attacker can exploit this to cause a denial of service (DoS) condition. The vulnerability affects versions 8.x, 9.x, and 10.x, and has been addressed in versions 9.2.15 and 10.1.4.
Affected products
- Apache Traffic Server 8.0.0 through 8.1.9, 9.0.0 through 9.2.14, 10.0.0 through 10.1.3
Timeline
- 2026-07-29: disclosed
- 2026-07-29: advisory