Apache Traffic Server Expect Header Field Vulnerability Allowing Resource Retention

Vulnerability

A vulnerability in Apache Traffic Server (ATS) in versions 9.0.0 through 9.2.8 and 10.0.0 through 10.0.3 allows the Expect header field to unreasonably retain resources. This issue could lead to unexpected behavior in how requests are processed, potentially causing resource management problems.

Impact

Exploitation of this vulnerability can lead to expected behavior violations, causing malformed requests to be improperly handled and resources to be retained longer than necessary.

Remediation

Users of Apache Traffic Server 9.x should upgrade to version 9.2.9 or later. Users of Apache Traffic Server 10.x should upgrade to version 10.0.4 or later.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
5.2
impact
0.6
exploitability
7.6
remediation
7.7
relevance
0.0
threat
0.0
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.