Memory Corruption Vulnerability in Apache Traffic Server Plugin
CVE-2026-58184

8.3HIGH

Key Information:

Vendor

Apache

Vendor
CVE Published:
29 July 2026

What is CVE-2026-58184?

The header_rewrite plugin in Apache Traffic Server is susceptible to a vulnerability that causes memory corruption or crashes during cookie operations and CIDR condition matching. This flaw can disrupt the normal functionality of the server, potentially impacting performance and reliability. Users of affected versions are strongly encouraged to upgrade to the latest versions, 9.2.15 or 10.1.4, to mitigate this issue and ensure their system remains stable.

Affected Version(s)

Apache Traffic Server 8.0.0 <= 8.1.9

Apache Traffic Server 9.0.0 <= 9.2.14

Apache Traffic Server 10.0.0 <= 10.1.3

References

CVSS V4

Score:
8.3
Severity:
HIGH
Confidentiality:
Low
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Omkhar Arasaratnam
.