Loading HuntDB...

GHSA-j49j-p46f-pfcv

GitHub Security Advisory

⚠ Unreviewed CRITICAL Has CVE

Advisory Details

Apache Traffic Server forwards malformed HTTP chunked trailer section to origin servers. This can be utilized for request smuggling and may also lead cache poisoning if the origin servers are vulnerable.

This issue affects Apache Traffic Server: from 8.0.0 through 8.1.10, from 9.0.0 through 9.2.4.

Users can set a new setting (proxy.config.http.drop_chunked_trailers) not to forward chunked trailer section.
Users are recommended to upgrade to version 8.1.11 or 9.2.5, which fixes the issue.

Related CVEs

Key Information

GHSA ID
GHSA-j49j-p46f-pfcv
Published
July 26, 2024 12:35 PM
Last Modified
November 4, 2025 12:30 AM
CVSS Score
9.0 /10
Primary Ecosystem
Unknown
Primary Package
Unknown
GitHub Reviewed
✗ No

Dataset

Last updated: November 24, 2025 6:29 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.