Transfer-Encoding not treated as hop-by-hop
3Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackepss 2.0%
exploitation probability
2.0%top 20% of all CVEs
observed exploitation
nono source reports it
Improper Input Validation vulnerability in handling the Transfer-Encoding header of Apache Traffic Server allows an attacker to poison the cache. This issue affects Apache Traffic Server 8.0.0 to 9.0.2.
Affected products
Apache Software Foundation · Apache Traffic Server