Junglewise Threat Intelligence

CVE-2026-58154: Apache Traffic Server out-of-bounds write in HTTP header parsing

CVE-2026-58154 · Severity: high · CVSS 8.9 · Published 2026-07-29

Technologies: Apache Traffic Server. Vendors: Apache.

Executive brief

Apache Traffic Server, a high-performance caching proxy used to manage web traffic, contains a vulnerability in how it processes web requests. An attacker could send specially crafted network traffic to cause the system to crash or potentially execute unauthorized commands. This could lead to service outages or a compromise of the server's integrity and data.

Technical details

Apache Traffic Server is vulnerable to an out-of-bounds write (CWE-787) and integer overflow during the parsing of MIME and HTTP headers. The vulnerability exists in the header processing logic where malformed inputs can lead to memory corruption. An unauthenticated remote attacker can exploit this by sending specifically crafted HTTP requests. Successful exploitation could result in a denial-of-service (DoS) condition or potentially remote code execution. The issue is fixed in versions 9.2.15 and 10.1.4.

Affected products

  • Apache Traffic Server 8.0.0 through 8.1.9, 9.0.0 through 9.2.14, 10.0.0 through 10.1.3

Timeline

  • 2026-07-29: disclosed
  • 2026-07-29: advisory

References