IP Access Control Bypass in Apache Traffic Server
CVE-2026-58159
7HIGH
What is CVE-2026-58159?
A serious issue has been identified in Apache Traffic Server that can allow unauthorized access by bypassing IP access control mechanisms on UDS listeners. This vulnerability arises from errors in access control list (ACL) matching, posing potential risks to network security. Users are advised to ensure their systems are updated to versions 9.2.15 or 10.1.4 to mitigate this vulnerability.
Affected Version(s)
Apache Traffic Server 8.0.0 <= 8.1.9
Apache Traffic Server 9.0.0 <= 9.2.14
Apache Traffic Server 10.0.0 <= 10.1.3