CVE-2022-25763

HIGH

Apache Traffic Server < 8.1.5 - HTTP Request Smuggling

Title source: rule
STIX 2.1

Description

Improper Input Validation vulnerability in HTTP/2 request validation of Apache Traffic Server allows an attacker to create smuggle or cache poison attacks. This issue affects Apache Traffic Server 8.0.0 to 9.1.2.

Scores

CVSS v3 7.5
EPSS 0.0044
EPSS Percentile 63.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-444
Status published
Products (4)
apache/traffic_server 8.0.0 - 8.1.5
debian/debian_linux 11.0
fedoraproject/fedora 35
fedoraproject/fedora 36
Published Aug 10, 2022
Tracked Since Feb 18, 2026