Apache Traffic Server allows request smuggling if chunked messages are malformed. 
This issue affects Apache Traffic Server: from 9.2.0 through 9.2.9, from 10.0.0 through 10.0.4.
Users are recommended to upgrade to version 9.2.10 or 10.0.5, which fixes the issue.
                
            Metrics
Affected Vendors & Products
References
        History
                    Wed, 16 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Metrics | 
        
        
        epss
         
  | 
    
        
        
        epss
         
  | 
Tue, 29 Apr 2025 21:00:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| First Time appeared | 
        
        Apache
         Apache traffic Server  | 
|
| CPEs | cpe:2.3:a:apache:traffic_server:*:*:*:*:*:*:*:* | |
| Vendors & Products | 
        
        Apache
         Apache traffic Server  | 
Fri, 18 Apr 2025 15:15:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Metrics | 
        
        cvssV3_1
         
 
  | 
Thu, 03 Apr 2025 09:45:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| References | 
         | 
Thu, 03 Apr 2025 09:15:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Description | Apache Traffic Server allows request smuggling if chunked messages are malformed. This issue affects Apache Traffic Server: from 9.2.0 through 9.2.9, from 10.0.0 through 10.0.4. Users are recommended to upgrade to version 9.2.10 or 10.0.5, which fixes the issue. | |
| Title | Apache Traffic Server: Malformed chunked message body allows request smuggling | |
| Weaknesses | CWE-444 | |
| References | 
         | 
Status: PUBLISHED
Assigner: apache
Published: 2025-04-03T08:59:02.557Z
Updated: 2025-04-18T14:38:03.477Z
Reserved: 2024-11-22T19:01:29.833Z
Link: CVE-2024-53868
Updated: 2025-04-03T09:03:43.467Z
Status : Analyzed
Published: 2025-04-03T09:15:15.780
Modified: 2025-04-29T20:42:23.407
Link: CVE-2024-53868
No data.