Request Smuggling Vulnerability in Apache Traffic Server
CVE-2025-65114

7.5HIGH

Key Information:

Vendor

Apache

Vendor
CVE Published:
2 April 2026

What is CVE-2025-65114?

Apache Traffic Server is vulnerable to request smuggling due to mishandling of malformed chunked messages. This issue can potentially allow attackers to forge requests and manipulate web traffic, leading to unauthorized access or data leakage. Affected versions include 9.0.0 through 9.2.12 and 10.0.0 through 10.1.1. Users are strongly urged to upgrade to versions 9.2.13 or 10.1.2 to mitigate this security risk.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

Apache Traffic Server 9.0.0 <= 9.2.12

Apache Traffic Server 10.0.0 <= 10.1.1

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Katsutoshi Ikenoya
.