HomeSecurityApache Traffic Server: Vulnerabilities allow DoS attacks

Apache Traffic Server: Vulnerabilities allow DoS attacks

The Apache Software Foundation has released emergency security updates to address two critical vulnerabilities in Apache Traffic Server (ATS), one of the most widely used web traffic management tools in enterprise environments. ATS is widely used as a high-performance proxy and caching server, handling huge volumes of data and optimizing network performance on a global scale.

Apache Traffic Server

These vulnerabilities affect the way the server processes HTTP requests with message bodies, opening the way for attacks that can cause anything from system downtime to data breaches.

CVE-2025-58136: A simple HTTP request can crash the server

The first and most immediate threat concerns the vulnerability CVE-2025-58136, discovered by researcher Masakazu Kitajo. What is particularly worrying is that even a standard HTTP POST request can cause Apache Traffic Server to crash.

Since POST requests are widely used in everyday online transactions, it is extremely easy for a remote attacker to exploit the vulnerability. The result is an immediate Denial-of-Service (DoS) attack, rendering the server inoperable and interrupting access for all users.

See also: Google DeepMind: How do hackers breach AI Agents?

In business environments, this can mean downtime, loss of revenue, and severe disruption of critical services.

CVE-2025-65114: HTTP request smuggling and stealth attacks

The second vulnerability, CVE-2025-65114, discovered by Katsutoshi Ikenoya, concerns the incorrect handling of chunked message bodies during data transmission.

This flaw allows HTTP request smuggling attacks . This is an advanced technique that allows attackers to manipulate the way servers and downstream systems process requests. Through this method, attackers can bypass security mechanisms, poison caches, or gain access to sensitive data .

Unlike DoS attacks, smuggling attacks are more difficult to detect, as they operate "silently" within the flow of normal traffic.

Apache Traffic Server: Vulnerabilities allow DoS attacks

Which versions are affected and who is at risk?

According to the official announcement, the vulnerabilities affect multiple versions of ATS, specifically 9.0.0 to 9.2.12 and 10.0.0 to 10.1.1. This means that a large number of organizations using these versions may be exposed.

Given the widespread use of Apache Traffic Server in CDNs, cloud infrastructures, and large corporate networks, the impact could be particularly widespread.

See also: CISA: TrueConf vulnerability in KEV Directory

Immediate actions and available patches

The Apache Software Foundation urges all administrators to upgrade immediately. For the 9.x branch, it is recommended to upgrade to version 9.1.13 or later, while for the 10.x branch, version 10.1.2 or later completely eliminates the vulnerabilities.

There is a workaround for the DoS vulnerability : disabling the proxy.config.http.request_buffer_enabled parameter . Fortunately, this is already the default setting, which reduces the immediate risk for some systems.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

However, for the request smuggling vulnerability there is no alternative to a full upgrade.

Why attacks on proxy servers are critical

Proxy servers are a key link in the online communication. Any breach in these systems can affect multiple layers of infrastructure, from applications to end users.

Attacks on such services allow attackers to control data flow, intercept information, or disrupt services on a large scale.

Apache Traffic Server: Vulnerabilities allow DoS attacks

The importance of timely information

This incident once again highlights the importance of promptly applying security updates. In an environment where attacks are becoming increasingly sophisticated, even small delays can create serious gaps.

See also: Axios npm hack: North Korean hackers use fake Teams error

Organizations are urged to adopt more proactive strategies, such as continuous monitoring, automated patching systems, and regular security audits.

The Apache Traffic Server case serves as a clear reminder that even mature and widely used tools are not invulnerable, and that cybersecurity remains an ongoing battle against evolving threats.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS