CVE-2021-37147
HIGH7.5EPSS 0.89%trafficserver - security update
Published: 11/3/2021Modified: 4/28/2026
Description
Improper input validation vulnerability in header parsing of Apache Traffic Server allows an attacker to smuggle requests. This issue affects Apache Traffic Server 8.0.0 to 8.1.2 and 9.0.0 to 9.1.0.
Affected packages (2)
- Debian/trafficserverfrom 0, < 8.1.1+ds-1.1+deb11u1
- Debian/trafficserverfrom 0, < 8.0.2+ds-1+deb10u6
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | HIGH7.5 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N |