logo

Apache Traffic Server Vulnerabilities Let Attackers Trigger DoS Attack

ID: 94cfe57f-e737-5c51-a7ba-ca622e13a667

STIX ID: report--94cfe57f-e737-5c51-a7ba-ca622e13a667

Feed Name: cybersecurityNews.com

Threat Score
70/100

Date Published: 2026-04-06

Date Updated: 2026-04-21

Author: Abinaya

...
...

The Apache Software Foundation issued emergency patches for two critical Apache Traffic Server vulnerabilities—CVE-2025-58136 (remote DoS via a crafted POST) and CVE-2025-65114 (HTTP request smuggling via malformed chunked bodies). Affected ATS versions include 9.0.0–9.2.12 and 10.0.0–10.1.1; administrators are urged to upgrade to 9.1.13 or 10.1.2+ immediately. A config change can mitigate the DoS (proxy.config.http.request_buffer_enabled = 0) but there is no workaround for the request smuggling issue.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.