CVE-2025-31698

CVE-2025-31698: Apache Traffic Server: Client IP address from PROXY protocol is not used for ACL

Vendor Apache Software Foundation
Product Apache Traffic Server
Weakness CWE-284
Published June 19, 2025
Last update June 20, 2025

CVSS base score

What the vulnerability does

Description

ACL configured in ip_allow.config or remap.config does not use IP addresses that are provided by PROXY protocol. Users can use a new setting (proxy.config.acl.subjects) to choose which IP addresses to use for the ACL if Apache Traffic Server is configured to accept PROXY protocol.  This issue affects undefined: from 10.0.0 through 10.0.6, from 9.0.0 through 9.2.10. Users are recommended to upgrade to version 9.2.11 or 10.0.6, which fixes the issue.

Key dates

Disclosure timeline

June 19, 2025 CVE published
June 20, 2025 Record updated