GHSA-j49j-p46f-pfcv
GitHub Security Advisory
⚠ Unreviewed
CRITICAL
Has CVE
Advisory Details
Apache Traffic Server forwards malformed HTTP chunked trailer section to origin servers. This can be utilized for request smuggling and may also lead cache poisoning if the origin servers are vulnerable.
This issue affects Apache Traffic Server: from 8.0.0 through 8.1.10, from 9.0.0 through 9.2.4.
Users can set a new setting (proxy.config.http.drop_chunked_trailers) not to forward chunked trailer section.
Users are recommended to upgrade to version 8.1.11 or 9.2.5, which fixes the issue.
Related CVEs
Key Information
9.0
/10
Dataset
Last updated: November 24, 2025 6:29 AM
Data from GitHub Advisory Database. This information is provided for research and educational purposes.