← All credits
Apache Community
25 vulnerability records and advisories credit this contributor.
CVE-2026-65324
Apache Traffic Server: HTTP/2 and HTTP/3 dechunking removes per-stream buffer cap, allowing memory exhaustion
CVE-2026-65100
Apache Traffic Server: HPACK encoder desynchronizes from the decoder after a failed header encode
CVE-2026-58188
Apache Traffic Server: Memory-safety and limit-bypass errors across experimental plugins
CVE-2026-58181
Apache Traffic Server: uri_signing and url_sig plugins can exhaust the stack or crash
CVE-2026-58180
Apache Traffic Server: txn_box plugin overflows the stack from attacker input
CVE-2026-58179
Apache Traffic Server: regex_remap plugin overflows the stack from attacker input
CVE-2026-58178
Apache Traffic Server: ESI plugin allows uncontrolled recursion and server-side request forgery
CVE-2026-58164
Apache Traffic Server: Remap configuration lifetime and TOCTOU errors cause use-after-free
CVE-2026-58163
Apache Traffic Server: Cache deserialization and lifetime errors can corrupt state or crash the server
CVE-2026-58160
Apache Traffic Server: Out-of-bounds reads while parsing DNS responses