IP Handling Vulnerability in Apache Traffic Server
CVE-2025-31698
Currently unrated
What is CVE-2025-31698?
The vulnerability arises from an incorrect configuration of access control lists (ACLs) in the Apache Traffic Server which fails to utilize IP addresses provided through the PROXY protocol. This misconfiguration can lead to unauthorized access if not properly managed. Users can resolve this issue by enabling the new setting (proxy.config.acl.subjects) to specify the appropriate IP sources for the ACL when PROXY protocol support is enabled. It is recommended to update to versions 9.2.11 or 10.0.6 to mitigate this vulnerability.
Affected Version(s)
Apache Traffic Server 10.0.0 <= 10.0.6
Apache Traffic Server 9.0.0 <= 9.2.10