Loading HuntDB...

GHSA-68qf-xhq3-9qj5

GitHub Security Advisory

⚠ Unreviewed HIGH Has CVE

Advisory Details

Apache Traffic Server accepts characters that are not allowed for HTTP field names and forwards malformed requests to origin servers. This can be utilized for request smuggling and may also lead cache poisoning if the origin servers are vulnerable.

This issue affects Apache Traffic Server: from 8.0.0 through 8.1.10, from 9.0.0 through 9.2.4.

Users are recommended to upgrade to version 8.1.11 or 9.2.5, which fixes the issue.

Related CVEs

Key Information

GHSA ID
GHSA-68qf-xhq3-9qj5
Published
July 26, 2024 12:35 PM
Last Modified
August 1, 2024 3:32 PM
CVSS Score
7.5 /10
Primary Ecosystem
Unknown
Primary Package
Unknown
GitHub Reviewed
✗ No

Dataset

Last updated: July 29, 2025 6:37 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.