CVE-2020-9494: High severity apache traffic server vulnerability
Apache Traffic Server 6.0.0 to 6.2.3, 7.0.0 to 7.1.10, and 8.0.0 to 8.0.7 is vulnerable to certain types of HTTP/2 HEADERS frames that can cause the server to allocate a large amount of memory and spin the thread.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-9494?
CVE-2020-9494 is a vulnerability in Apache Traffic Server that allows the server to allocate a large amount of memory and spin the thread when certain types of HTTP/2 HEADERS frames are received.
How severe is CVE-2020-9494?
CVE-2020-9494 has a severity level of 7.5 (high).
Which software versions are affected by CVE-2020-9494?
Apache Traffic Server versions 6.0.0 to 6.2.3, 7.0.0 to 7.1.10, and 8.0.0 to 8.0.7 are affected by CVE-2020-9494.
How can I fix CVE-2020-9494?
To fix CVE-2020-9494, update your Apache Traffic Server to version 8.0.8 or higher.
Where can I find more information about CVE-2020-9494?
You can find more information about CVE-2020-9494 on the Debian security tracker and MITRE CVE website.