Apache Traffic Server reuses multiplexed HTTP/2 origin connections without verifying the server certificate covers the new request hostname. This issue affects Apache Traffic Server: from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.
We have discovered 369 live websites that are affected by CVE-2026-65325.
| Product | |
| Category | Web Servers |
| Vulnerable Domains | 369 live websites (35% of ATS install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 11 versions ( 44% of all versions) |
| 34 websites | |
| 131 websites | |
| 124 websites | |
| 36 websites | |
| 8 websites | |
| 7 websites | |
| 5 websites | |
| 5 websites | |
| 5 websites | |
| 4 websites |
| .com.cn | 88 websites |
| .com | 59 websites |
| .cn | 23 websites |
| .org | 22 websites |
| .de | 20 websites |
| .org.uk | 11 websites |
| .net | 10 websites |
| .it | 8 websites |
| .ru | 7 websites |
| .fi | 7 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| ****.******.jp | **,*** | ||
| ***.**********.de | **,*** | ||
| *********.******.***.cn | **,*** | ||
| ******.**********.de | ***,*** | ||
| ******.***.cn | ***,*** | ||
| *****.******.***.cn | ***,*** | ||
| ***.***.**.uk | ***,*** | ||
| ****.******.***.cn | ***,*** | ||
| *****.****.******.community | ***,*** | ||
| *****.****.******.community | ***,*** |
FAQ