CVE-2025-31698 - CVE House
Back to Database
Status published Unknown CVE-2025-31698

Apache Traffic Server: Client IP address from PROXY protocol is not used for ACL

Vulnerability Description

ACL configured in ip_allow.config or remap.config does not use IP addresses that are provided by PROXY protocol. Users can use a new setting (proxy.config.acl.subjects) to choose which IP addresses to use for the ACL if Apache Traffic Server is configured to accept PROXY protocol.  This issue affects undefined: from 10.0.0 through 10.0.6, from 9.0.0 through 9.2.10. Users are recommended to upgrade to version 9.2.11 or 10.0.6, which fixes the issue.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-31698

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Apache Software Foundation

View all reports →

Affected Software

Apache Traffic Server
Vulnerable Versions:
10.0.0, 9.0.0

Timeline

Official Publish: June 19th, 2025
Last Modified: June 20th, 2025
Added to House: July 22nd, 2026

CVSS Vectors

No vector data available

Weaknesses (CWE)