Apache Traffic Server URL Mis-parsing Vulnerability
CVE-2026-58156
6.3MEDIUM
What is CVE-2026-58156?
A mis-parsing issue in Apache Traffic Server compromises the proper handling of ports in URLs and userinfo fields. This flaw allows unauthorized access to resources due to improper access control mechanisms, leading to potential security risks for affected users. It is crucial for organizations utilizing versions 8.0.0 through 8.1.9, 9.0.0 through 9.2.14, and 10.0.0 through 10.1.3 to upgrade to the patched versions 9.2.15 or 10.1.4 to safeguard their systems.
Affected Version(s)
Apache Traffic Server 8.0.0 <= 8.1.9
Apache Traffic Server 9.0.0 <= 9.2.14
Apache Traffic Server 10.0.0 <= 10.1.3