Impact
Memory-safety errors in MIME and HTTP header parsing in Apache Traffic Server enable an attacker to trigger out‑of‑bounds writes or integer overflows. These defects can lead to arbitrary code execution or privilege escalation when the server processes specially crafted traffic. The weakness is categorized as CWE‑787, a classic buffer overflow scenario that jeopardises confidentiality, integrity, and availability of the server.
Affected Systems
The vulnerability affects Apache Software Foundation’s Traffic Server versions 8.0.0 through 8.1.9, 9.0.0 through 9.2.14, and 10.0.0 through 10.1.3. All builds within those ranges are impacted by this memory‑safety flaw.
Risk and Exploitability
The CVSS score of 9.2 indicates a critical severity. The EPSS score of less than 1% suggests that, as of the latest data, exploitation remains unlikely but non‑zero. It is not currently listed in CISA’s KEV catalog, though the flaw could be actively reflected if an attacker crafts malicious HTTP requests targeting header parsing. The attack vector appears to be remote network, requiring the attacker to send specifically malformed MIME or HTTP headers to a reachable Traffic Server instance. No exploitation prerequisites beyond connectivity are described, so the risk remains high for exposed servers.
OpenCVE Enrichment