Apache Traffic Server Patches “Double-Header” DoS and Request Smuggling Flaws
ID: 9143f380-f307-5064-8da5-38f5bc53f92a
STIX ID: report--9143f380-f307-5064-8da5-38f5bc53f92a
Feed Name: securityonline.info
Apache Traffic Server is affected by two high-severity vulnerabilities (both CVSS 7.5): CVE-2025-58136 causes server crashes when handling certain POST requests (DoS), and CVE-2025-65114 permits request smuggling when chunked messages are malformed, risking data interception or session interference. Affected versions include 10.0.0–10.1.1 and 9.0.0–9.2.12; administrators are advised to upgrade to 10.1.2 or 9.2.13. A mitigation for the POST crash is to set proxy.config.http.request_buffer_enabled to 0 if immediate patching is not possible.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
