CVE-2022-47185

Apache Traffic Server: Invalid Range header causes a crash

Improper input validation vulnerability on the range header in Apache Software Foundation Apache Traffic Server.This issue affects Apache Traffic Server: through 9.2.1.


We have discovered 733 live websites that are affected by CVE-2022-47185.

Run a Free Instant Scan




Affected Software

Product  ATS
Category Web Servers
Vulnerable Domains733 live websites (66% of ATS install base)
Vulnerable Versions
  • from 0 through 9.2.1
Vulnerable Versions Count16 versions ( 59% of all versions)


Common Weakness Enumeration

CWE-20 Improper Input Validation



Details

  • Published - Aug 9, 2023
  • Updated - Feb 13, 2025

Credits

  • Katsutoshi Ikenoya (finder)

Website Distribution by Country

Number of websites using CVE-2022-47185
United States52 websites



China550 websites
Germany27 websites
France19 websites
Singapore17 websites
Canada8 websites
Spain8 websites
Romania8 websites
Russia7 websites
Finland6 websites

Website Distribution by TLD

Number of websites using CVE-2022-47185
.com.cn397 websites
.cn137 websites
.com104 websites
.de14 websites
.org13 websites
.ru11 websites
.net10 websites
.fi9 websites
.es4 websites
.eu4 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2022-47185

Top websites that are affected by CVE-2022-47185. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*.*******.cn China*,***
****.***.cn China*,***
*******.****.***.cn China*,***
***.***.******.cn China*,***
******.****.***.cn China*,***
***.*.******.cn China*,***
****.****.***.cn China*,***
*****.******.cn China*,***
****.****.***.cn China*,***
****.****.***.cn China*,***
See full domain list

FAQ

CVE-2022-47185 is Improper Input Validation in ATS
A total of 733 websites have been identified as vulnerable to CVE-2022-47185, based on global website indexing conducted by WebTechSurvey.
The ATS is affected by the CVE-2022-47185 vulnerability.
ATS versions up to and including 9.2.1 are vulnerable to CVE-2022-47185.