CVE-2024-56202

Apache Traffic Server: Expect header field can unreasonably retain resource

Expected Behavior Violation vulnerability in Apache Traffic Server. This issue affects Apache Traffic Server: from 9.0.0 through 9.2.8, from 10.0.0 through 10.0.3. Users are recommended to upgrade to versions 9.2.9 or 10.0.4 or newer, which fixes the issue.


We have discovered 1,317 live websites that are affected by CVE-2024-56202.

Test my site




Affected Software

Product  ATS
Category Web Servers
Vulnerable Domains1,317 live websites (61.60% of ATS install base)
Vulnerable Versions
  • from 9 through 9.2.8
  • from 10 through 10.0.3
Vulnerable Versions Count14 versions ( 35.90% of all versions)


Common Weakness Enumeration

CWE-440 Expected Behavior Violation



Details

  • Published - Mar 6, 2025
  • Updated - Mar 6, 2025

Credits

  • David Carlin (reporter)

CVE-2024-56202 usage by Country

United States1,047 websites



Germany170 websites
GB38 websites
Italy26 websites
Isle of Man7 websites
Netherlands6 websites
China3 websites
France3 websites
Canada2 websites
India2 websites

CVE-2024-56202 usage by TLD

.org883 websites
.com148 websites
.net57 websites
.it38 websites
.de33 websites
.org.uk11 websites
.edu10 websites
.co.uk3 websites
.ca2 websites
.com.br2 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2024-56202

Top websites that are affected by CVE-2024-56202. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
**.*********.org United States**
*******.com United States**
**.*********.org United States***
*******.*********.org United States***
**.*********.org United States***
*********.org United States*,***
*********.org United States*,***
**.*********.org United States*,***
**.*********.org United States*,***
************.net United States*,***
See full domain list

FAQ

CVE-2024-56202 is Expected Behavior Violation in ATS
A total of 1,317 websites have been identified as vulnerable to CVE-2024-56202, discovered through global website indexing conducted by WebTechSurvey.
ATS is susceptible to CVE-2024-56202 vulnerability.
ATS versions before, and including, 10.0.3 are vulnerable to CVE-2024-56202.