POST Request Handling Bug in Apache Traffic Server Affects Multiple Versions
CVE-2025-58136

7.5HIGH

Key Information:

Vendor

Apache

Vendor
CVE Published:
2 April 2026

What is CVE-2025-58136?

A vulnerability in the POST request handling of Apache Traffic Server can lead to crashes when specific conditions are met. This issue affects versions 10.0.0 to 10.1.1 and 9.0.0 to 9.2.12. Users are advised to update to the latest versions, 10.1.2 or 9.2.13, which resolve the issue. For those unable to upgrade, setting the configuration option 'proxy.config.http.request_buffer_enabled' to 0 can serve as a temporary workaround.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

Apache Traffic Server 10.0.0 <= 10.1.1

Apache Traffic Server 9.0.0 <= 9.2.12

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.