Technology · Apache
Apache Traffic Server vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 39 vulnerabilities in Apache Traffic Server: 0 in the last 7 days and 37 in the last 90 days, 6 of them critical and 0 exploited in the wild. The most recent, CVE-2026-65100, was published on 29 July 2026.
- Last 7 days
- 0
- Last 90 days
- 37
- Critical, all time
- 6
- Exploited in the wild
- 0
About Apache Traffic Server
Traffic Server is a high-performance HTTP proxy and caching server.
Latest Apache Traffic Server vulnerabilities
- CVE-2026-65100: Apache Traffic Server HTTP/2 HPACK dynamic table corruptionmediumCVSS 4.8
- CVE-2026-58189: Apache Traffic Server SSRF amplification via redirect-limit bypasshighCVSS 7.5
- CVE-2026-58188: Apache Traffic Server memory safety and limit bypass in experimental pluginshighCVSS 8.2
- CVE-2026-58187: Apache Traffic Server out-of-bounds write in multiplexer pluginlowCVSS 3.7
- CVE-2026-58186: Apache Traffic Server unsafe decoding in webp_transform pluginhighCVSS 7.5
- CVE-2026-58184: Apache Traffic Server memory corruption in header_rewrite pluginhighCVSS 8.2
- CVE-2026-58183: Apache Traffic Server denial of service in prefetch pluginmediumCVSS 5.9
- CVE-2026-58182: Apache Traffic Server state mishandling in ts_lua pluginhighCVSS 8.6
- CVE-2026-58181: Apache Traffic Server stack exhaustion in uri_signing and url_sig pluginshighCVSS 7.5
- CVE-2026-58180: Apache Traffic Server stack overflow in txn_box pluginhighCVSS 7.5
- CVE-2026-58179: Apache Traffic Server stack overflow in regex_remap pluginhighCVSS 8.1
- CVE-2026-58178: Apache Traffic Server uncontrolled recursion in ESI pluginhighCVSS 7.5
- CVE-2026-58177: Apache Traffic Server multiple vulnerabilities in Cripts frameworkhighCVSS 8.1
- CVE-2026-58175: Apache Traffic Server memory leak in HostDB SRV record handlinghighCVSS 7.5
- CVE-2026-58164: Apache Traffic Server use-after-free in remap configuration handlinghighCVSS 7.5
- CVE-2026-58163: Apache Traffic Server deserialization vulnerability in cache componenthighCVSS 7.5
- CVE-2026-58162: Apache Traffic Server improper certificate validation in certifier plugincriticalCVSS 10
- CVE-2026-58161: Apache Traffic Server denial of service in TLS and SNI handlinghighCVSS 7.5
- CVE-2026-58160: Apache Traffic Server out-of-bounds read in DNS parsingmediumCVSS 6.5
- CVE-2026-58158: Apache Traffic Server stack overflow in PROXY protocol handlingmediumCVSS 5.9
- CVE-2026-58157: Apache Traffic Server session and tunnel reuse data exposurehighCVSS 8.7
- CVE-2026-65325: Apache Traffic Server improper certificate validation in HTTP/2 origin reusemediumCVSS 4.8
- CVE-2026-65324: Apache Traffic Server memory exhaustion in HTTP/2 and HTTP/3 dechunkinghighCVSS 7.5
- CVE-2026-58156: Apache Traffic Server port-based access control bypassmediumCVSS 4.9
- CVE-2026-58155: Apache Traffic Server request smuggling via header truncationcriticalCVSS 9.3
Most severe Apache Traffic Server vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2026-58162: Apache Traffic Server improper certificate validation in certifier plugincriticalCVSS 10
- CVE-2026-58150: Apache Traffic Server request smuggling in HTTP/2 downgradecriticalCVSS 10
- CVE-2026-57834: Apache Traffic Server request smuggling via malformed chunked messagescriticalCVSS 10
- CVE-2026-33267: Apache Traffic Server improper input validationcriticalCVSS 10
- CVE-2026-58155: Apache Traffic Server request smuggling via header truncationcriticalCVSS 9.3
- CVE-2026-41920: Apache Traffic Server improper access controlcriticalCVSS 9.3
- CVE-2026-58154: Apache Traffic Server out-of-bounds write in HTTP header parsinghighCVSS 8.9
- CVE-2026-58157: Apache Traffic Server session and tunnel reuse data exposurehighCVSS 8.7
- CVE-2026-58182: Apache Traffic Server state mishandling in ts_lua pluginhighCVSS 8.6
- CVE-2026-58153: Apache Traffic Server HTTP smuggling via improper HTTP/2 to HTTP/1 framinghighCVSS 8.3
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 29 Jun 2026 | 0 | 0 | |
| 6 Jul 2026 | 0 | 0 | |
| 13 Jul 2026 | 1 | 0 | |
| 20 Jul 2026 | 0 | 0 | |
| 27 Jul 2026 | 36 | 6 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 0 | 0 | |
| 17 Aug 2026 | 0 | 0 | |
| 24 Aug 2026 | 0 | 0 | |
| 31 Aug 2026 | 0 | 0 | |
| 7 Sep 2026 | 0 | 0 | |
| 14 Sep 2026 | 0 | 0 | |
| 21 Sep 2026 | 0 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/technologies/traffic-server.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "Apache Traffic Server vulnerabilities", https://junglewise.ai/threats/technologies/traffic-server, 26 September 2026.