logo

Apache Traffic Server Flaw Allowed Attackers to Trigger Denial-of-Service Attacks

ID: e24f70ff-544b-572a-a31f-99d56e5b4372

STIX ID: report--e24f70ff-544b-572a-a31f-99d56e5b4372

Feed Name: GBHackers

Threat Score
75/100

Date Published: 2026-04-06

Date Updated: 2026-04-22

Author: Divya

...
...

Apache released critical security updates for Apache Traffic Server to fix two vulnerabilities: CVE-2025-58136 (unauthenticated POST can crash the server causing DoS) and CVE-2025-65114 (HTTP request smuggling via malformed chunked bodies that can enable cache poisoning, bypass of controls, or data interception). Affected versions include ATS 9.x (9.0.0–9.2.12) and 10.x (10.0.0–10.1.1); administrators should upgrade to 9.1.13 or 10.1.2+ immediately, and may temporarily mitigate the DoS by setting proxy.config.http.request_buffer_enabled to 0, while no workaround exists for the request smuggling issue.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.