Junglewise Threat Intelligence

CVE-2026-58163: Apache Traffic Server deserialization vulnerability in cache component

CVE-2026-58163 · Severity: high · CVSS 7.5 · Published 2026-07-29

Technologies: Apache Traffic Server. Vendors: Apache.

Executive brief

Apache Traffic Server, a high-performance caching proxy used to speed up web content delivery, contains a flaw in how it manages stored data. An attacker could exploit this to corrupt the server's internal state or cause the service to crash. This could lead to service outages or the delivery of incorrect data to users, impacting business operations and reliability.

Technical details

Apache Traffic Server is vulnerable to a state corruption issue due to the improper handling of on-disk cache fields and object lifetimes. The vulnerability is classified as a deserialization of untrusted data (CWE-502) within the caching component. An unauthenticated remote attacker can exploit this flaw to corrupt the cache state or trigger a denial-of-service (DoS) condition by crashing the server. The issue affects versions 8.x, 9.x, and 10.x, and has been addressed in versions 9.2.15 and 10.1.4.

Affected products

  • Apache Traffic Server 8.0.0 through 8.1.9, 9.0.0 through 9.2.14, 10.0.0 through 10.1.3

Timeline

  • 2026-07-29: disclosed
  • 2026-07-29: advisory
  • 2026-07-29: patched

References