Out of Bounds Write Vulnerability in Apache Traffic Server
CVE-2026-58154
9.2CRITICAL
What is CVE-2026-58154?
Apache Traffic Server is susceptible to a vulnerability that allows it to write data outside of its intended memory space or experience integer overflow. This occurs when the server parses MIME and HTTP headers, leading to potential exploitation opportunities. To mitigate this vulnerability, users are advised to upgrade to Apache Traffic Server version 9.2.15 or 10.1.4, where the issue has been addressed.
Affected Version(s)
Apache Traffic Server 8.0.0 <= 8.1.9
Apache Traffic Server 9.0.0 <= 9.2.14
Apache Traffic Server 10.0.0 <= 10.1.3
References
CVSS V4
Score:
9.2
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Michael Bommarito
Apache Community
Omkhar Arasaratnam