Apache · Apache Traffic Server · CVE-2023-39456
**Name of the Vulnerable Software and Affected Versions**
Apache Traffic Server versions 9.0.0 through 9.2.2
**Description**
The issue is related to an Improper Input Validation vulnerability in Apache Traffic Server, specifically with malformed HTTP/2 frames. Users are recommended to upgrade to a fixed version.
**Recommendations**
For Apache Traffic Server versions 9.0.0 through 9.2.2, upgrade to version 9.2.3, which fixes the issue.