CVE-2014-3624: Apache Traffic Server

Critical severity, CVSS 9.8. EPSS: 3.8% chance of exploitation in the next 30 days.

Apache Traffic Server 5.1.x before 5.1.1 allows remote attackers to bypass access restrictions by leveraging failure to properly tunnel remap requests using CONNECT.

Affected products

  • Apache Traffic Server: version 5.1.0 only

Published 2017-10-30. Last modified 2026-06-17.