CVE-2022-28129: Insufficient Validation of HTTP/1.x Headers
Improper Input Validation vulnerability in HTTP/1.1 header parsing of Apache Traffic Server allows an attacker to send invalid headers. This issue affects Apache Traffic Server 8.0.0 to 9.1.2.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-28129?
CVE-2022-28129 is classified as an improper input validation vulnerability that can lead to potential security risks in affected Apache Traffic Server versions.
How do I fix CVE-2022-28129?
To mitigate CVE-2022-28129, upgrade your Apache Traffic Server to version 8.1.7-0+deb10u2, 9.2.0+ds-2+deb12u1, or a later version.
Which versions of Apache Traffic Server are affected by CVE-2022-28129?
CVE-2022-28129 affects Apache Traffic Server versions from 8.0.0 up to and including 9.1.2.
Is CVE-2022-28129 specific to any operating system?
CVE-2022-28129 affects Apache Traffic Server installations on various operating systems including Debian and Fedora.
What type of attacks can CVE-2022-28129 potentially facilitate?
CVE-2022-28129 can allow attackers to send invalid HTTP headers, which may lead to denial of service or further exploitation.