Impact
Apache Traffic Server is vulnerable to HTTP Request/Response Smuggling caused by a flaw in the parsing of extension quoted-strings within chunked transfer encoding. The inconsistent interpretation allows an attacker to craft a single HTTP request that the server forwards as multiple requests to downstream services. This can bypass security controls, enable denial‑of‑service, or facilitate the injection of forged requests that may lead to data disclosure or remote code execution if combined with other vulnerabilities. The weakness is classified as CWE‑444.
Affected Systems
Affected versions include Apache Traffic Server 9.0.0 through 9.2.14 and 10.0.0 through 10.1.3. The vendor, Apache Software Foundation, recommends upgrading to any of the advisably fixed releases: 9.2.15 or 10.1.4. Each product runs on standard web server platforms that handle HTTP traffic from external clients.
Risk and Exploitability
The CVSS score of 6.9 indicates a moderate severity vulnerability. The EPSS score of less than 1% suggests that exploit activity is currently low and the vulnerability is unlikely to be widely used in the wild. The issue is not listed in the CISA KEV catalog. Exploitation would involve sending crafted chunked requests from an external network, requiring no privileged access on the target. Because the flaw affects only HTTP parsing, mitigating network traffic can reduce exploitation probability.
OpenCVE Enrichment