CVE-2022-25763

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
10/08/2022
Last modified:
20/10/2025

Description

Improper Input Validation vulnerability in HTTP/2 request validation of Apache Traffic Server allows an attacker to create smuggle or cache poison attacks. This issue affects Apache Traffic Server 8.0.0 to 9.1.2.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:apache:traffic_server:*:*:*:*:*:*:*:* 8.0.0 (including) 8.1.5 (excluding)
cpe:2.3:a:apache:traffic_server:*:*:*:*:*:*:*:* 9.0.0 (including) 9.1.3 (excluding)
cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:35:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:36:*:*:*:*:*:*:*