This issue affects Apache Traffic Server: from 8.0.0 through 8.1.10, from 9.0.0 through 9.2.4.
Users can set a new setting (proxy.config.http.drop_chunked_trailers) not to forward chunked trailer section.
Users are recommended to upgrade to version 8.1.11 or 9.2.5, which fixes the issue.
No analysis available yet.
No remediation available yet.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-3897-1 | trafficserver security update |
Debian DSA |
DSA-5758-1 | trafficserver security update |
Mon, 03 Nov 2025 22:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Mon, 03 Nov 2025 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
ssvc
|
Wed, 28 May 2025 17:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
Thu, 22 May 2025 02:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
Mon, 09 Sep 2024 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-20 |
Tue, 03 Sep 2024 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-20 | |
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Tue, 13 Aug 2024 09:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-20 |
Mon, 12 Aug 2024 14:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Apache
Apache traffic Server |
|
| Weaknesses | CWE-444 | |
| CPEs | cpe:2.3:a:apache:traffic_server:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Apache
Apache traffic Server |
|
| Metrics |
cvssV3_1
|
cvssV3_1
|
Status: PUBLISHED
Assigner: apache
Published:
Updated: 2025-11-03T21:54:57.527Z
Reserved: 2024-05-09T20:04:47.056Z
Link: CVE-2024-35161
Updated: 2025-11-03T21:54:57.527Z
Status : Modified
Published: 2024-07-26T10:15:02.567
Modified: 2025-11-03T22:16:55.883
Link: CVE-2024-35161
OpenCVE Enrichment
No data.
Debian DLA
Debian DSA