Apache Traffic Server Denial-of-Service Vulnerability in POST Request Handling

Vulnerability

A denial-of-service vulnerability has been identified in Apache Traffic Server (ATS) versions 9.0.0 through 9.2.12 and 10.0.0 through 10.1.1. The issue arises from a bug in the handling of POST requests, which under certain conditions, leads to a crash. Users of older ATS versions can set 'proxy.config.http.request_buffer_enabled' to 0, the default value, as a temporary workaround.

Impact

Exploitation of this vulnerability causes a crash of the Apache Traffic Server, leading to a denial-of-service condition.

Remediation

Users of Apache Traffic Server 9.x should upgrade to version 9.2.13 or later. Users of Apache Traffic Server 10.x should upgrade to version 10.1.2 or later.

Added: Apr 2, 2026, 7:39 PM
Updated: Apr 2, 2026, 7:39 PM

Vulnerability Rating

Custom Algorithm
spread
5.2
impact
2.5
exploitability
7.6
remediation
8.3
relevance
5.1
threat
0.0
urgency
2.9
incentive
4.2

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.