CVE-2024-53868

Apache Traffic Server: Malformed chunked message body allows request smuggling

Apache Traffic Server allows request smuggling if chunked messages are malformed.  This issue affects Apache Traffic Server: from 9.2.0 through 9.2.9, from 10.0.0 through 10.0.4. Users are recommended to upgrade to version 9.2.10 or 10.0.5, which fixes the issue.


We have discovered 350 live websites that are affected by CVE-2024-53868.

Run a Free Instant Scan




Affected Software

Product  ATS
Category Web Servers
Vulnerable Domains350 live websites (31% of ATS install base)
Vulnerable Versions
  • from 9.2 through 9.2.9
  • from 10 through 10.0.4
Vulnerable Versions Count8 versions ( 30% of all versions)


Common Weakness Enumeration

CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')



Details

  • Published - Apr 3, 2025
  • Updated - Apr 18, 2025

Credits

  • Jeppe Bonde Weikop (reporter)

Website Distribution by Country

Number of websites using CVE-2024-53868
United States47 websites



China124 websites
Germany109 websites
GB35 websites
Isle of Man8 websites
France7 websites
Italy7 websites
Canada4 websites
Japan2 websites
Russia2 websites

Website Distribution by TLD

Number of websites using CVE-2024-53868
.com.cn88 websites
.com72 websites
.cn22 websites
.org20 websites
.org.uk11 websites
.it11 websites
.net8 websites
.pl3 websites
.ru3 websites
.ca2 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2024-53868

Top websites that are affected by CVE-2024-53868. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
********.************.net United States**,***
****.******.jp Japan**,***
*********.******.***.cn China**,***
******.***.cn China***,***
*****.******.***.cn China***,***
***.***.**.uk GB***,***
****.******.***.cn China***,***
*****.****.******.community Germany***,***
*****.****.******.community Germany***,***
*****.****.******.community Germany***,***
See full domain list

FAQ

CVE-2024-53868 is Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') in ATS
A total of 350 websites have been identified as vulnerable to CVE-2024-53868, based on global website indexing conducted by WebTechSurvey.
The ATS is affected by the CVE-2024-53868 vulnerability.
ATS versions up to and including 10.0.4 are vulnerable to CVE-2024-53868.