CVE Database
/

CVE-2022-25763

Back to search

CVE-2022-25763

Published: Aug 10, 2022

Modified: Oct 20, 2025

PUBLISHED

Description

Improper Input Validation vulnerability in HTTP/2 request validation of Apache Traffic Server allows an attacker to create smuggle or cache poison attacks. This issue affects Apache Traffic Server 8.0.0 to 9.1.2.

VendorProductVersions

Apache Software Foundation

Apache Traffic Server

affected
8.0.0 to 9.1.2

Weaknesses (CWE)

References

DSA-5206
vendor-advisory
x_refsource_DEBIAN
FEDORA-2022-9832c0c04b
vendor-advisory
x_refsource_FEDORA
FEDORA-2022-23043f5a0b
vendor-advisory
x_refsource_FEDORA

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now