CVE-2024-50306: Apache Traffic Server
Critical severity, CVSS 9.1. EPSS: 1.6% chance of exploitation in the next 30 days.
Unchecked return value can allow Apache Traffic Server to retain privileges on startup. This issue affects Apache Traffic Server: from 9.2.0 through 9.2.5, from 10.0.0 through 10.0.1. Users are recommended to upgrade to version 9.2.6 or 10.0.2, which fixes the issue.
Affected products
- Apache Traffic Server: from 9.0.0, before 9.2.6 (fixed in 9.2.6); from 10.0.0, before 10.0.2 (fixed in 10.0.2)
Published 2024-11-14. Last modified 2026-06-17.