Junglewise Threat Intelligence

CVE-2026-58155: Apache Traffic Server request smuggling via header truncation

CVE-2026-58155 · Severity: critical · CVSS 9.3 · Published 2026-07-29

Technologies: Apache Traffic Server. Vendors: Apache.

Executive brief

Apache Traffic Server, a high-performance caching proxy used to manage and speed up web traffic, contains a vulnerability in how it handles web request headers. By sending specially crafted, overly long headers, an attacker can trick the server into misinterpreting requests. This could allow unauthorized users to bypass security policies, access restricted data, or interfere with the communication between users and the backend web servers.

Technical details

A request smuggling vulnerability (CWE-444) exists in Apache Traffic Server due to improper handling of excessively long HTTP header names. The server truncates these headers, which can lead to header aliasing where a malicious header is misinterpreted as a legitimate one by downstream or upstream components. An unauthenticated remote attacker can exploit this to bypass security policies or perform request smuggling attacks. The issue affects versions 8.x, 9.x, and 10.x, and is resolved in versions 9.2.15 and 10.1.4.

Affected products

  • Apache Traffic Server 8.0.0 through 8.1.9, 9.0.0 through 9.2.14, 10.0.0 through 10.1.3

Timeline

  • 2026-07-29: disclosed
  • 2026-07-29: advisory

References

Related threats