CVE-2021-32565: HTTP Request Smuggling, content length with invalid charters
Invalid values in the Content-Length header sent to Apache Traffic Server allows an attacker to smuggle requests. This issue affects Apache Traffic Server 7.0.0 to 7.1.12, 8.0.0 to 8.1.1, 9.0.0 to 9.0.1.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-32565?
CVE-2021-32565 is a vulnerability in Apache Traffic Server that allows an attacker to smuggle requests by sending invalid values in the Content-Length header.
Which versions of Apache Traffic Server are affected by CVE-2021-32565?
CVE-2021-32565 affects Apache Traffic Server versions 7.0.0 to 7.1.12, 8.0.0 to 8.1.1, and 9.0.0 to 9.0.1.
What is the severity of CVE-2021-32565?
CVE-2021-32565 has a severity rating of 7.5 (high).
How can I fix CVE-2021-32565?
To fix CVE-2021-32565, update your Apache Traffic Server to version 8.0.2+ds-1+deb10u6, 8.1.7-0+deb10u2, 8.1.7+ds-1~deb11u1, 9.2.0+ds-2+deb12u1, or 9.2.2+ds-1.
Where can I find more information about CVE-2021-32565?
You can find more information about CVE-2021-32565 at the following references: [Link 1](https://lists.apache.org/thread.html/ra1a41ff92a70d25bf576d7da2590575e8ff430393a3f4a0c34de4277%40%3Cannounce.trafficserver.apache.org%3E), [Link 2](https://github.com/apache/trafficserver/pull/7945), [Link 3](https://github.com/apache/trafficserver/commit/668d0f8668fec1cd350b0ceba3f7f8e4020ae3ca).