Exposure of Apache Traffic Server

Web servers
123
exposure score
3,251
sites use
0
exploited
7
critical
Vexday analysis

Com 63 CVEs catalogadas e nenhuma confirmada em exploração ativa pelo catálogo CISA KEV, o Apache Traffic Server apresenta taxa de exploração abaixo da média geral, o que pode refletir sua presença em ambientes mais especializados. No entanto, o alto escore EPSS de 0,94615 registrado na CVE-2024-31309 — associada a falhas de validação de entrada (CWE-20, o tipo de falha mais frequente nessa tecnologia) — indica probabilidade elevada de exploração, exigindo atenção prioritária independentemente da ausência de confirmações KEV. Das 63 vulnerabilidades, 3 são classificadas como críticas, e 2 surgiram nos últimos 90 dias, sinalizando uma superfície de ataque ainda ativa. Equipes que operam o Apache Traffic Server devem tratar CVE-2024-31309 como prioridade imediata de remediação, dado o risco quantificado pelo modelo preditivo EPSS.

CVEs

102 results
CVE-2026-58179CRITICALApache Traffic Server: regex_remap plugin overflows the stack from attacker inputEPSS 0.6%CVE-2026-58184HIGHApache Traffic Server: header_rewrite plugin cookie handling can corrupt memoryEPSS 0.6%CVE-2026-58177HIGHApache Traffic Server: Memory-safety and path-traversal errors in the Cripts frameworkEPSS 0.6%CVE-2026-33930HIGHApache Traffic Server: Buffer overflow via Host field that has a long string valueEPSS 0.6%CVE-2026-58158HIGHApache Traffic Server: PROXY protocol parsing has port truncation and a stack overflowEPSS 0.6%CVE-2026-58152MEDIUMApache Traffic Server: Integer-handling errors in HPACK/XPACK decoding corrupt memoryEPSS 0.6%CVE-2026-58187MEDIUMApache Traffic Server: Multiplexer plugin chunk decoder enables a denial of serviceEPSS 0.6%CVE-2026-65100MEDIUMApache Traffic Server: HPACK encoder desynchronizes from the decoder after a failed header encodeEPSS 0.6%CVE-2026-58185HIGHApache Traffic Server: Use-after-free in the intercept pluginEPSS 0.6%CVE-2026-58160MEDIUMApache Traffic Server: Out-of-bounds reads while parsing DNS responsesEPSS 0.6%CVE-2026-24033MEDIUMApache Traffic Server: Request smuggling via chunked extension quoted-string parsingEPSS 0.6%CVE-2026-58150HIGHApache Traffic Server: HTTP/2 requests with Transfer-Encoding are not rejected, allowing request smugglingEPSS 0.6%CVE-2026-58159HIGHApache Traffic Server: Listener and ACL handling allow access-control bypassEPSS 0.6%CVE-2025-31698HIGHApache Traffic Server: Client IP address from PROXY protocol is not used for ACLEPSS 0.6%CVE-2026-58155CRITICALApache Traffic Server: Header-name length truncation enables header aliasing and request smugglingEPSS 0.5%CVE-2026-58154CRITICALApache Traffic Server: Memory-safety errors in MIME and header parsingEPSS 0.5%CVE-2026-41920HIGHApache Traffic Server: SNI to Host header matching policy is not properly enforcedEPSS 0.5%CVE-2026-58157MEDIUMApache Traffic Server: Improper server-session reuse can expose data across client connectionsEPSS 0.5%CVE-2025-65114HIGHApache Traffic Server: Malformed chunked message body allows request smugglingEPSS 0.4%CVE-2026-58156MEDIUMApache Traffic Server: URL and port parsing errors allow access-control bypassEPSS 0.4%