TROYANOSYVIRUS
Back to CVEs

CVE-2023-38522

HIGH
7.5

Description

Apache Traffic Server accepts characters that are not allowed for HTTP field names and forwards malformed requests to origin servers. This can be utilized for request smuggling and may also lead cache poisoning if the origin servers are vulnerable. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.10, from 9.0.0 through 9.2.4. Users are recommended to upgrade to version 8.1.11 or 9.2.5, which fixes the issue.

CVE Details

CVSS v3.1 Score7.5
SeverityHIGH
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Attack VectorNETWORK
ComplexityLOW
Privileges RequiredNONE
User InteractionNONE
Published7/26/2024
Last Modified11/3/2025
Sourcenvd
Honeypot Sightings0

Affected Products

apache:traffic_server

Weaknesses (CWE)

CWE-444CWE-444

IOC Correlations

No correlations recorded

This product uses data from the NVD API but is not endorsed or certified by the NVD.