CVE-2021-32565

HIGH

Apache Traffic Server 7.0.0-7.1.12, 8.0.0-8.1.1, 9.0.0-9.0.1 - HTTP Request Smuggling via Content-Length Header

Title source: llm
STIX 2.1

Description

Invalid values in the Content-Length header sent to Apache Traffic Server allows an attacker to smuggle requests. This issue affects Apache Traffic Server 7.0.0 to 7.1.12, 8.0.0 to 8.1.1, 9.0.0 to 9.0.1.

References (2)

Core 2
Core References
Third Party Advisory vendor-advisory x_refsource_debian
https://www.debian.org/security/2021/dsa-4957

Scores

CVSS v3 7.5
EPSS 0.0214
EPSS Percentile 79.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

Details

CWE
CWE-444
Status published
Products (2)
apache/traffic_server 7.0.0 - 7.1.12
debian/debian_linux 10.0
Published Jun 29, 2021
Tracked Since Feb 18, 2026