CVE-2025-31698

Apache Traffic Server: Client IP address from PROXY protocol is not used for ACL

ACL configured in ip_allow.config or remap.config does not use IP addresses that are provided by PROXY protocol. Users can use a new setting (proxy.config.acl.subjects) to choose which IP addresses to use for the ACL if Apache Traffic Server is configured to accept PROXY protocol.  This issue affects undefined: from 10.0.0 through 10.0.6, from 9.0.0 through 9.2.10. Users are recommended to upgrade to version 9.2.11 or 10.0.6, which fixes the issue.


We have discovered 378 live websites that are affected by CVE-2025-31698.

Run a Free Instant Scan




Affected Software

Product  ATS
Category Web Servers
Vulnerable Domains378 live websites (34% of ATS install base)
Vulnerable Versions
  • from 9 through 9.2.10
  • from 10 through 10.0.6
Vulnerable Versions Count10 versions ( 37% of all versions)


Common Weakness Enumeration

CWE-284 Improper Access Control



Details

  • Published - Jun 19, 2025
  • Updated - Jun 20, 2025

Website Distribution by Country

Number of websites using CVE-2025-31698
United States49 websites



Germany126 websites
China125 websites
GB35 websites
Isle of Man8 websites
France7 websites
Italy7 websites
Finland5 websites
Canada4 websites
Russia4 websites

Website Distribution by TLD

Number of websites using CVE-2025-31698
.com.cn88 websites
.com77 websites
.cn22 websites
.org20 websites
.de12 websites
.org.uk11 websites
.it11 websites
.net10 websites
.fi7 websites
.ru5 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2025-31698

Top websites that are affected by CVE-2025-31698. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
********.************.net United States**,***
****.******.jp Japan**,***
***.**********.de Germany**,***
*********.******.***.cn China**,***
******.**********.de Germany***,***
******.***.cn China***,***
*****.******.***.cn China***,***
***.***.**.uk GB***,***
****.******.***.cn China***,***
*****.****.******.community Germany***,***
See full domain list

FAQ

CVE-2025-31698 is Improper Access Control in ATS
A total of 378 websites have been identified as vulnerable to CVE-2025-31698, based on global website indexing conducted by WebTechSurvey.
The ATS is affected by the CVE-2025-31698 vulnerability.
ATS versions up to and including 10.0.6 are vulnerable to CVE-2025-31698.