Apache Traffic Server
cpe:2.3:a:apache:traffic_server:*:*:*:*:*:*:*
- >= 9.0.0, <= 9.2.8
- >= 10.0.0, <= 10.0.3
A vulnerability in Apache Traffic Server (ATS) in versions 9.0.0 through 9.2.8 and 10.0.0 through 10.0.3 allows the Expect header field to unreasonably retain resources. This issue could lead to unexpected behavior in how requests are processed, potentially causing resource management problems.
Exploitation of this vulnerability can lead to expected behavior violations, causing malformed requests to be improperly handled and resources to be retained longer than necessary.
Users of Apache Traffic Server 9.x should upgrade to version 9.2.9 or later. Users of Apache Traffic Server 10.x should upgrade to version 10.0.4 or later.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.