Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2024-31309

74
FAUCET Score

CVE-2024-31309 describes an HTTP/2 CONTINUATION DoS vulnerability in Apache Traffic Server versions 8.0.0 through 8.1.9 and 9.0.0 through 9.2.3, allowing attackers to consume excessive server resources. With a CVSS score of 7.5 (High), this network-based attack requires low complexity and no user interaction, potentially leading to high availability impact. While there is no known active exploitation or public exploit code, the vulnerability has garnered significant community discussion and media coverage, indicating awareness and potential for future exploitation. Users are advised to upgrade to versions 8.1.10 or 9.2.4 to mitigate this risk.

Impacted Technologies

VendorProductVersion(s)CPE
>= 8.0.0, < 8.1.10CPE matchmatch criteria
cpe:2.3:a:apache:traffic_server:*:*:*:*:*:*:*:*
>= 9.0.0, < 9.2.4CPE matchmatch criteria
cpe:2.3:a:apache:traffic_server:*:*:*:*:*:*:*:*
10.0CPE matchmatch criteria
cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*
38CPE matchmatch criteria
cpe:2.3:o:fedoraproject:fedora:38:*:*:*:*:*:*:*
39CPE matchmatch criteria
cpe:2.3:o:fedoraproject:fedora:39:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

7.5HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
HIGH
Exploitability Score
3.9
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
94.62%
Probability of exploitation in next 30 days
EPSS Percentile
99.8%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.9462 is in the 100th percentile among its peer group of 51,551 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Advisories (1)

redhatCVE-2024-31309Important

trafficserver: CONTINUATION frames DoS

Apr 3, 2024

References

kb.cert.org / vuls/id/421644
lists.apache.org / thread/f9qh3g3jvy153wh82pz4onrfj1wh13kc
Mailing ListVendor Advisory
lists.debian.org / debian-lts-announce/2024/04/msg00021.html
Mailing ListThird Party Advisory
lists.fedoraproject.org / archives/list/[email protected]/message/PBKLPQ6ECG4PGEPRCYI3Y3OITNDEFCCV
Third Party Advisory
lists.fedoraproject.org / archives/list/[email protected]/message/QV77HYM7ARSTL3B6U3IFG7PHDU65WL4I
Third Party Advisory
lists.fedoraproject.org / archives/list/[email protected]/message/T3XON6RM5ZKCZ6K6NB7BOTAWMJQKXJDO
Third Party Advisory
openwall.com / lists/oss-security/2024/04/03/16
Mailing List
openwall.com / lists/oss-security/2024/04/10/7
Mailing List