Executive brief
Apache Traffic Server, a high-performance caching proxy used to manage web traffic, contains vulnerabilities in several of its experimental plugins. These flaws could allow an attacker to bypass security limits or cause the system to crash, potentially leading to service outages. Organizations using these specific plugins should update to the latest patched versions to ensure service availability and security.
Technical details
Apache Traffic Server experimental plugins are affected by memory-safety issues, specifically identified as out-of-bounds writes (CWE-787), and limit-bypass errors. These vulnerabilities can be triggered remotely over the network without authentication. Successful exploitation could lead to a denial-of-service (DoS) condition or allow an attacker to circumvent configured traffic limits. The issue impacts versions 8.x, 9.x, and 10.x; users are advised to upgrade to versions 9.2.15 or 10.1.4.
Affected products
- Apache Traffic Server 8.0.0 to 8.1.9, 9.0.0 to 9.2.14, 10.0.0 to 10.1.3
Timeline
- 2026-07-29: disclosed
- 2026-07-29: advisory