Regular Expression Vulnerability in Apache Traffic Server by Apache Software Foundation
CVE-2026-22068

6.9MEDIUM

Key Information:

Vendor

Apache

Vendor
CVE Published:
29 July 2026

What is CVE-2026-22068?

A vulnerability exists in Apache Traffic Server due to improper handling of regular expressions without anchors. This flaw can lead to unexpected behavior and potential security risks in the processing of network traffic. Users are strongly encouraged to upgrade to version 9.2.15 or 10.1.4 to remediate this vulnerability and enhance the security posture of their systems.

Affected Version(s)

Apache Traffic Server 10.0.x <= 10.1.3

Apache Traffic Server 9.0.x <= 9.2.14

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Omkhar Arasaratnam
Apache Community
.