Junglewise Threat Intelligence

CVE-2026-58159: Apache Traffic Server IP access control bypass in UDS listeners and ACLs

CVE-2026-58159 · Severity: high · CVSS 8.2 · Published 2026-07-29

Vendors: Apache Software Foundation.

Executive brief

Apache Traffic Server, a high-performance caching proxy used to manage web traffic, contains a security flaw that allows unauthorized users to bypass IP-based access restrictions. This could allow attackers to access internal resources or administrative interfaces that should be restricted to specific trusted networks. Organizations using this software should upgrade to the latest versions to ensure their network access controls remain effective.

Technical details

An incorrect authorization vulnerability (CWE-863) exists in Apache Traffic Server due to errors in how Access Control Lists (ACLs) are matched and how IP access controls are applied to Unix Domain Socket (UDS) listeners. A remote, unauthenticated attacker can exploit these logic errors to bypass intended network restrictions. The issue affects versions 8.x, 9.x, and 10.x. The vulnerability is resolved in versions 9.2.15 and 10.1.4.

Affected products

  • Apache Software Foundation Traffic Server 8.0.0 through 8.1.9, 9.0.0 through 9.2.14, 10.0.0 through 10.1.3

Timeline

  • 2026-07-29: disclosed
  • 2026-07-29: advisory

References