Junglewise Threat Intelligence

CVE-2026-58158: Apache Traffic Server stack overflow in PROXY protocol handling

CVE-2026-58158 · Severity: medium · CVSS 5.9 · Published 2026-07-29

Technologies: Apache Traffic Server. Vendors: Apache.

Executive brief

Apache Traffic Server, a high-performance caching proxy used to manage web traffic, contains a vulnerability in how it handles specific network connection data. An attacker could exploit this flaw to cause the server to crash, leading to a denial of service for users and applications relying on the proxy. Organizations should update to the latest versions to ensure service availability and stability.

Technical details

A stack-based buffer overflow (CWE-121) exists in Apache Traffic Server due to improper handling of PROXY protocol input. The vulnerability occurs when the server processes malformed PROXY protocol headers, leading to port truncation and a stack overflow. This is a network-based attack that does not require authentication, though the CVSS vector suggests high complexity (AC:H), likely due to specific configuration requirements or timing. Successful exploitation primarily impacts service availability by causing a crash (Denial of Service). The issue is resolved in versions 9.2.15 and 10.1.4.

Affected products

  • Apache Traffic Server 8.0.0 through 8.1.9, 9.0.0 through 9.2.14, 10.0.0 through 10.1.3

Timeline

  • 2026-07-29: disclosed
  • 2026-07-29: advisory
  • 2026-07-29: patched

References

Related threats