CVE-2024-38311

Apache Traffic Server: Request smuggling via pipelining after a chunked message body

Improper Input Validation vulnerability in Apache Traffic Server. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.11, from 9.0.0 through 9.2.8, from 10.0.0 through 10.0.3. Users are recommended to upgrade to version 9.2.9 or 10.0.4, which fixes the issue.


We have discovered 400 live websites that are affected by CVE-2024-38311.

Run a Free Instant Scan




Affected Software

Product  ATS
Category Web Servers
Vulnerable Domains400 live websites (36% of ATS install base)
Vulnerable Versions
  • from 8 through 8.1.11
  • from 9 through 9.2.8
  • from 10 through 10.0.3
Vulnerable Versions Count13 versions ( 48% of all versions)


Common Weakness Enumeration

CWE-20 Improper Input Validation



Details

  • Published - Mar 6, 2025
  • Updated - Mar 6, 2025

Credits

  • Ben Kallus (reporter)

Website Distribution by Country

Number of websites using CVE-2024-38311
United States49 websites



Germany132 websites
China131 websites
GB35 websites
France10 websites
Isle of Man8 websites
Spain7 websites
Russia7 websites
Italy6 websites
Finland5 websites

Website Distribution by TLD

Number of websites using CVE-2024-38311
.com.cn93 websites
.com82 websites
.org26 websites
.cn22 websites
.de13 websites
.ru11 websites
.org.uk11 websites
.it10 websites
.fi8 websites
.net6 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2024-38311

Top websites that are affected by CVE-2024-38311. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
********.************.net United States**,***
****.******.jp Japan**,***
********.******.com United States**,***
************.******.com United States**,***
***.**********.de Germany**,***
*********.******.com United States**,***
*********.******.***.cn China**,***
******.**********.de Germany***,***
******.***.cn China***,***
*****.******.***.cn China***,***
See full domain list

FAQ

CVE-2024-38311 is Improper Input Validation in ATS
A total of 400 websites have been identified as vulnerable to CVE-2024-38311, based on global website indexing conducted by WebTechSurvey.
The ATS is affected by the CVE-2024-38311 vulnerability.
ATS versions up to and including 10.0.3 are vulnerable to CVE-2024-38311.