Exposure of Apache Traffic Server

Web servers
123
exposure score
3,251
sites use
0
exploited
7
critical
Vexday analysis

Com 63 CVEs catalogadas e nenhuma confirmada em exploração ativa pelo catálogo CISA KEV, o Apache Traffic Server apresenta taxa de exploração abaixo da média geral, o que pode refletir sua presença em ambientes mais especializados. No entanto, o alto escore EPSS de 0,94615 registrado na CVE-2024-31309 — associada a falhas de validação de entrada (CWE-20, o tipo de falha mais frequente nessa tecnologia) — indica probabilidade elevada de exploração, exigindo atenção prioritária independentemente da ausência de confirmações KEV. Das 63 vulnerabilidades, 3 são classificadas como críticas, e 2 surgiram nos últimos 90 dias, sinalizando uma superfície de ataque ainda ativa. Equipes que operam o Apache Traffic Server devem tratar CVE-2024-31309 como prioridade imediata de remediação, dado o risco quantificado pelo modelo preditivo EPSS.

CVEs

102 results
CVE-2026-59173HIGHApache Traffic Server: DoS vulnerability in HTTP/2 via stalled flow-control conditionsEPSS 0.7%CVE-2026-58182HIGHApache Traffic Server: ts_lua plugin has initialization and resource-handling errorsEPSS 0.7%CVE-2026-58186HIGHApache Traffic Server: webp_transform plugin decodes unsafely and mislabels degraded responsesEPSS 0.7%CVE-2026-58163HIGHApache Traffic Server: Cache deserialization and lifetime errors can corrupt state or crash the serverEPSS 0.7%CVE-2025-58136HIGHApache Traffic Server: A simple legitimate POST request causes a crashEPSS 0.7%CVE-2026-58161CRITICALApache Traffic Server: Memory-safety errors in TLS and SNI handling can crash the serverEPSS 0.7%CVE-2026-58151HIGHApache Traffic Server: Abusive HTTP/2 framing can exhaust resources and crash the serverEPSS 0.7%CVE-2026-58164HIGHApache Traffic Server: Remap configuration lifetime and TOCTOU errors cause use-after-freeEPSS 0.7%CVE-2026-58180HIGHApache Traffic Server: txn_box plugin overflows the stack from attacker inputEPSS 0.7%CVE-2026-58178HIGHApache Traffic Server: ESI plugin allows uncontrolled recursion and server-side request forgeryEPSS 0.7%CVE-2026-58175HIGHApache Traffic Server: HostDB SRV handling leaks memoryEPSS 0.7%CVE-2026-65324HIGHApache Traffic Server: HTTP/2 and HTTP/3 dechunking removes per-stream buffer cap, allowing memory exhaustionEPSS 0.7%CVE-2026-58181HIGHApache Traffic Server: uri_signing and url_sig plugins can exhaust the stack or crashEPSS 0.7%CVE-2026-58183HIGHApache Traffic Server: prefetch plugin can crash on attacker-influenced inputEPSS 0.7%CVE-2024-53868HIGHApache Traffic Server: Malformed chunked message body allows request smugglingEPSS 0.6%CVE-2026-58153MEDIUMApache Traffic Server: HTTP/2 to HTTP/1 conversion forwards origin trailers to clients unsafelyEPSS 0.6%CVE-2026-58189HIGHApache Traffic Server: Plugins resetting the redirect counter enable SSRF amplificationEPSS 0.6%CVE-2026-57834HIGHApache Traffic Server: Malformed chunked message body allows request smugglingEPSS 0.6%CVE-2026-22068MEDIUMApache Traffic Server: Regex mappings match with malicious domain namesEPSS 0.6%CVE-2026-33267HIGHApache Traffic Server: Untrusted @ headers can spoof ATS internal metadataEPSS 0.6%