Home

Description

Apache Traffic Server allows request smuggling if chunked messages are malformed. This issue affects Apache Traffic Server: from 9.0.0 through 9.2.12, from 10.0.0 through 10.1.1. Users are recommended to upgrade to version 9.2.13 or 10.1.2, which fix the issue.

PUBLISHED Reserved 2025-11-18 | Published 2026-04-02 | Updated 2026-04-02 | Assigner apache

Problem types

CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')

Product status

Default status
unaffected

9.0.0 (semver)
affected

10.0.0 (semver)
affected

Credits

Katsutoshi Ikenoya reporter

References

lists.apache.org/thread/2s11roxlv1j8ph6q52rqo1klvl01n14q vendor-advisory

cve.org (CVE-2025-65114)

nvd.nist.gov (CVE-2025-65114)

Download JSON