Junglewise Threat Intelligence

CVE-2026-58157: Apache Traffic Server session and tunnel reuse data exposure

CVE-2026-58157 · Severity: high · CVSS 8.7 · Published 2026-07-29

Technologies: Apache Traffic Server. Vendors: Apache.

Executive brief

Apache Traffic Server, a high-performance caching proxy used to manage web traffic, contains a flaw that improperly reuses internal communication channels between different users. This could allow one user to inadvertently access or intercept data belonging to another user's session. Organizations using affected versions should upgrade to the latest patched releases to prevent potential data exposure and maintain user privacy.

Technical details

Apache Traffic Server is vulnerable to information exposure (CWE-200) due to the improper reuse of server sessions and tunnels. The flaw allows data from one client connection to be exposed to another when the proxy incorrectly recycles backend connections. This is a network-based attack that does not require authentication, though it may require specific timing or high-concurrency conditions (reflected in the High Attack Complexity). The issue affects versions 8.x, 9.x, and 10.x, and has been addressed in versions 9.2.15 and 10.1.4.

Affected products

  • Apache Traffic Server 8.0.0 through 8.1.9, 9.0.0 through 9.2.14, 10.0.0 through 10.1.3

Timeline

  • 2026-07-29: disclosed
  • 2026-07-29: advisory

References