CVE-2017-7671: Apache Traffic Server

High severity, CVSS 7.5. EPSS: 2.2% chance of exploitation in the next 30 days.

There is a DOS attack vulnerability in Apache Traffic Server (ATS) 5.2.0 to 5.3.2, 6.0.0 to 6.2.0, and 7.0.0 with the TLS handshake. This issue can cause the server to coredump.

Affected products

  • Apache Traffic Server: from 5.2.0, up to and including 5.3.2; after 6.0.0, up to and including 6.2.0; version 7.0.0 only
  • Debian Debian Linux: version 9.0 only

Published 2018-02-27. Last modified 2026-06-17.