# CVE-2024-56202

## Summary

- **CVE ID:** CVE-2024-56202
- **Severity:** UNKNOWN
- **CVSS Score:** 0
- **CWE:** CWE-440
- **Published:** Mar 6, 2025
- **Last Modified:** Mar 13, 2026

## Description

Expected Behavior Violation vulnerability in Apache Traffic Server.

This issue affects Apache Traffic Server: from 9.0.0 through 9.2.8, from 10.0.0 through 10.0.3.

Users are recommended to upgrade to versions 9.2.9 or 10.0.4 or newer, which fixes the issue.

## Affected Products

- Apache Software Foundation — Apache Traffic Server (9.0.0)
- Apache Software Foundation — Apache Traffic Server (10.0.0)

## References

- [CNA](https://lists.apache.org/thread/btofzws2yqskk2n7f01r3l1819x01023)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.85%
- **EPSS Percentile:** 56.0

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-10._