CVE-2022-28129

HIGH

Apache Traffic Server 8.0.0-9.1.2 - Improper Input Validation in HTTP/1.1 Header Parsing

Title source: llm
STIX 2.1

Description

Improper Input Validation vulnerability in HTTP/1.1 header parsing of Apache Traffic Server allows an attacker to send invalid headers. This issue affects Apache Traffic Server 8.0.0 to 9.1.2.

Scores

CVSS v3 7.5
EPSS 0.0319
EPSS Percentile 87.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

Details

CWE
CWE-20
Status published
Products (5)
apache/traffic_server 8.0.0 - 8.1.4
debian/debian_linux 10.0
debian/debian_linux 11.0
fedoraproject/fedora 35
fedoraproject/fedora 36
Published Aug 10, 2022
Tracked Since Feb 18, 2026