Junglewise Threat Intelligence

CVE-2026-58162: Apache Traffic Server improper certificate validation in certifier plugin

CVE-2026-58162 · Severity: critical · CVSS 10 · Published 2026-07-29

Technologies: Apache Traffic Server. Vendors: Apache.

Executive brief

Apache Traffic Server, a high-performance web proxy used to manage internet traffic, contains a critical flaw in its certificate generation plugin. An attacker can manipulate the system into generating fraudulent security certificates by providing malicious connection information. This could allow an attacker to impersonate legitimate websites, intercept sensitive data, or disrupt web services, potentially leading to a total loss of system integrity.

Technical details

A vulnerability exists in the Apache Traffic Server 'certifier' plugin due to improper certificate validation (CWE-295). The plugin generates SSL/TLS certificates based on the Server Name Indication (SNI) provided by the client, which is attacker-controlled. A remote, unauthenticated attacker can exploit this by sending a crafted SNI during the TLS handshake, causing the server to generate and potentially serve unauthorized certificates. This can lead to man-in-the-middle attacks or service disruption. The issue is resolved in versions 9.2.15 and 10.1.4.

Affected products

  • Apache Traffic Server 8.0.0 to 8.1.9, 9.0.0 to 9.2.14, 10.0.0 to 10.1.3

Timeline

  • 2026-07-29: advisory: Initial publication of CVE-2026-58162
  • 2026-07-29: disclosed

References

Related threats