Apache Traffic Server Vulnerabilities Let Attackers Trigger DoS Attack
ID: 94cfe57f-e737-5c51-a7ba-ca622e13a667
STIX ID: report--94cfe57f-e737-5c51-a7ba-ca622e13a667
Feed Name: cybersecurityNews.com
The Apache Software Foundation issued emergency patches for two critical Apache Traffic Server vulnerabilities—CVE-2025-58136 (remote DoS via a crafted POST) and CVE-2025-65114 (HTTP request smuggling via malformed chunked bodies). Affected ATS versions include 9.0.0–9.2.12 and 10.0.0–10.1.1; administrators are urged to upgrade to 9.1.13 or 10.1.2+ immediately. A config change can mitigate the DoS (proxy.config.http.request_buffer_enabled = 0) but there is no workaround for the request smuggling issue.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
