CVE-2020-17509: Apache Traffic Server

High severity, CVSS 7.5. EPSS: 1.8% chance of exploitation in the next 30 days.

ATS negative cache option is vulnerable to a cache poisoning attack. If you have this option enabled, please upgrade or disable this feature. Apache Traffic Server versions 7.0.0 to 7.1.11 and 8.0.0 to 8.1.0 are affected.

Affected products

  • Apache Traffic Server: from 6.0.0, up to and including 6.2.3; from 7.0.0, up to and including 7.1.10; from 8.0.0, up to and including 8.0.7

Published 2021-01-11. Last modified 2026-06-17.