Out of Bounds Read Vulnerability in Apache Traffic Server
CVE-2026-58160

6.3MEDIUM

Key Information:

Vendor

Apache

Vendor
CVE Published:
29 July 2026

What is CVE-2026-58160?

An out of bounds read vulnerability exists in Apache Traffic Server while parsing DNS answers. This security flaw affects versions 8.0.0 through 8.1.9, 9.0.0 through 9.2.14, and 10.0.0 through 10.1.3. Users are advised to upgrade to version 9.2.15 or 10.1.4, which addresses this issue and improves overall product security.

Affected Version(s)

Apache Traffic Server 8.0.0 <= 8.1.9

Apache Traffic Server 9.0.0 <= 9.2.14

Apache Traffic Server 10.0.0 <= 10.1.3

References

CVSS V4

Score:
6.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Apache Community
Omkhar Arasaratnam
.