Memory-Safety and Limit-Bypass Vulnerabilities in Apache Traffic Server Plugins
CVE-2026-58188
8.4HIGH
What is CVE-2026-58188?
Several experimental plugins for Apache Traffic Server have been identified with issues related to memory-safety and limit-bypass errors. These vulnerabilities can potentially allow unauthorized access and manipulation, putting network security at risk. Users are advised to upgrade to Apache Traffic Server version 9.2.15 or 10.1.4, which address these vulnerabilities and enhance overall safety.
Affected Version(s)
Apache Traffic Server 8.0.0 <= 8.1.9
Apache Traffic Server 9.0.0 <= 9.2.14
Apache Traffic Server 10.0.0 <= 10.1.3
References
CVSS V4
Score:
8.4
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Yon Harlicaj
Apache Community
Omkhar Arasaratnam