trafficserver

Direct Vulnerabilities

Known vulnerabilities in the trafficserver package. This does not include vulnerabilities belonging to this package’s dependencies.

Fix vulnerabilities automatically

Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.

Fix for free
VulnerabilityVulnerable Version
  • L
Improper Certificate Validation

*
  • L
Resource Exhaustion

*
  • L
Incorrect Behavior Order

*
  • L
Server-Side Request Forgery (SSRF)

*
  • L
Out-of-bounds Write

*
  • H
Out-of-bounds Write

*
  • L
Improper Input Validation

*
  • C
Use After Free

*
  • H
Out-of-bounds Write

*
  • H
Improper Input Validation

*
  • L
Resource Exhaustion

*
  • L
Stack-based Buffer Overflow

*
  • L
Stack-based Buffer Overflow

*
  • C
Stack-based Buffer Overflow

*
  • L
Uncontrolled Recursion

*
  • C
Out-of-bounds Write

*
  • L
Memory Leak

*
  • L
Use After Free

*
  • L
Deserialization of Untrusted Data

*
  • L
Improper Certificate Validation

*
  • L
NULL Pointer Dereference

*
  • L
Out-of-bounds Read

*
  • L
Incorrect Authorization

*
  • L
Stack-based Buffer Overflow

*
  • L
Information Exposure

*
  • L
Incorrect Authorization

*
  • L
HTTP Request Smuggling

*
  • L
Out-of-bounds Write

*
  • L
HTTP Request Smuggling

*
  • L
Integer Overflow or Wraparound

*
  • L
Resource Exhaustion

*
  • L
HTTP Request Smuggling

*
  • L
HTTP Request Smuggling

*
  • L
Improper Access Control

*
  • L
Stack-based Buffer Overflow

*
  • L
Improper Input Validation

*
  • L
HTTP Request Smuggling

*
  • L
Regular Expression without Anchors

*
  • L
Resource Exhaustion

*
  • L
HTTP Request Smuggling

<9.2.5+ds-0+deb12u4
  • L
Always-Incorrect Control Flow Implementation

<9.2.5+ds-0+deb12u4
  • L
Resource Exhaustion

<9.2.5+ds-0+deb12u3
  • L
Improper Access Control

<9.2.5+ds-0+deb12u3
  • L
CVE-2024-56202

<9.2.5+ds-0+deb12u2
  • L
CVE-2024-56195

<9.2.5+ds-0+deb12u2
  • L
HTTP Request Smuggling

<9.2.5+ds-0+deb12u3
  • L
Unchecked Return Value

<9.2.5+ds-0+deb12u2
  • L
Improper Input Validation

<9.2.5+ds-0+deb12u2
  • L
CVE-2024-38479

<9.2.5+ds-0+deb12u2
  • L
CVE-2024-38311

<9.2.5+ds-0+deb12u2
  • H
CVE-2024-35296

<9.2.5+ds-0+deb12u1
  • H
HTTP Request Smuggling

<9.2.5+ds-0+deb12u1
  • L
CVE-2024-31309

<9.2.4+ds-0+deb12u1
  • H
CVE-2023-44487

<9.2.3+ds-1+deb12u1
  • H
Information Exposure

<9.2.3+ds-1+deb12u1
  • H
Improper Input Validation

<9.2.3+ds-1+deb12u1
  • H
HTTP Request Smuggling

<9.2.5+ds-0+deb12u1
  • C
HTTP Request Smuggling

<9.2.3+ds-1+deb12u1
  • H
Information Exposure

<9.2.0+ds-2+deb12u1
  • H
Improper Input Validation

<9.2.0+ds-2+deb12u1
  • H
Improper Input Validation

<9.2.3+ds-1+deb12u1
  • H
Information Exposure

<9.2.0+ds-2+deb12u1
  • M
Cross-site Scripting (XSS)

<9.1.4+ds-1
  • M
Improper Check for Unusual or Exceptional Conditions

<9.1.4+ds-1
  • H
Improper Check for Unusual or Exceptional Conditions

<9.1.4+ds-1
  • H
Improper Input Validation

<9.1.3+ds-1
  • H
Improper Input Validation

<9.1.3+ds-1
  • H
Improper Input Validation

<9.1.3+ds-1
  • H
Improper Input Validation

<9.1.3+ds-1
  • H
HTTP Request Smuggling

<9.1.3+ds-1
  • H
Improper Authentication

<9.1.0+ds-1
  • H
Improper Input Validation

<9.1.2+ds-1
  • C
Buffer Overflow

<9.1.1+ds-1
  • H
Improper Authentication

<9.1.0+ds-1
  • H
Improper Input Validation

<9.1.3+ds-1
  • H
Improper Input Validation

<9.1.1+ds-1
  • H
Improper Input Validation

<9.1.1+ds-1
  • H
Improper Input Validation

<9.1.1+ds-1
  • C
Out-of-bounds Write

<8.1.1+ds-1.1
  • H
Improper Input Validation

<8.1.1+ds-1.1
  • H
Improper Input Validation

<8.1.1+ds-1.1
  • H
HTTP Request Smuggling

<8.1.1+ds-1.1
  • H
HTTP Request Smuggling

<8.1.1+ds-1.1
  • H
HTTP Request Smuggling

<8.1.1+ds-1
  • H
CVE-2020-17508

<8.1.1+ds-1
  • C
HTTP Request Smuggling

<8.0.6+ds-1
  • C
HTTP Request Smuggling

<8.0.6+ds-1
  • H
Allocation of Resources Without Limits or Throttling

<8.0.5+ds-1
  • H
Information Exposure

<8.0.2+ds-1
  • M
Out-of-Bounds

<5.2.0-1
  • H
Allocation of Resources Without Limits or Throttling

<8.0.8+ds-1
  • H
Resource Exhaustion

<8.0.7+ds-1
  • C
HTTP Request Smuggling

<8.0.6+ds-1
  • H
Allocation of Resources Without Limits or Throttling

<8.0.5+ds-1
  • H
Allocation of Resources Without Limits or Throttling

<8.0.5+ds-1
  • H
Allocation of Resources Without Limits or Throttling

<8.0.5+ds-1
  • H
Resource Exhaustion

<8.0.5+ds-1
  • M
Exposure of Resource to Wrong Sphere

<7.1.4+ds-1
  • H
Improper Input Validation

<7.0.0-1
  • M
Resource Exhaustion

<7.1.4+ds-1
  • M
HTTP Request Smuggling

<7.1.4+ds-1
  • H
Improper Input Validation

<7.1.4+ds-1
  • H
Improper Input Validation

<7.1.2+ds-1
  • H
Improper Input Validation

<7.1.2+ds-1
  • H
Improper Input Validation

<7.0.0-1
  • H
Resource Management Errors

<7.0.0-1
  • C
CVE-2015-5206

<6.0.0-1
  • C
CVE-2015-5168

<6.0.0-1
  • C
Out-of-Bounds

<5.3.1-1
  • C
Improper Access Control

<5.0.0-1
  • C
CVE-2014-3525

<5.0.1-1
  • M
Out-of-Bounds

<3.0.4-1