CVE-2012-0256: Apache Traffic Server
Medium severity, CVSS 5.0. EPSS: 3.4% chance of exploitation in the next 30 days.
Apache Traffic Server 2.0.x and 3.0.x before 3.0.4 and 3.1.x before 3.1.3 does not properly allocate heap memory, which allows remote attackers to cause a denial of service (daemon crash) via a long HTTP Host header.
Affected products
- Apache Traffic Server: version 2.0.0 only; version 2.0.1 only; version 2.1.0 only; version 2.1.1 only; version 2.1.2 only; version 2.1.3 only; …
Published 2012-03-26. Last modified 2026-06-16.