CVE-2017-5660: Apache Traffic Server

High severity, CVSS 8.6. EPSS: 1.9% chance of exploitation in the next 30 days.

There is a vulnerability in Apache Traffic Server (ATS) 6.2.0 and prior and 7.0.0 and prior with the Host header and line folding. This can have issues when interacting with upstream proxies and the wrong host being used.

Affected products

  • Apache Traffic Server: up to and including 6.2.0; version 6.2.1 only; version 6.2.2 only; version 7.0.0 only
  • Debian Debian Linux: version 9.0 only

Published 2018-02-27. Last modified 2026-06-17.