Junglewise Threat Intelligence

CVE-2026-58164: Apache Traffic Server use-after-free in remap configuration handling

CVE-2026-58164 · Severity: high · CVSS 7.5 · Published 2026-07-29

Technologies: Apache Traffic Server. Vendors: Apache.

Executive brief

Apache Traffic Server, a high-performance caching proxy used to manage web traffic and speed up content delivery, contains a vulnerability in how it handles configuration updates. An attacker could exploit this flaw to cause the service to crash, leading to a denial-of-service (DoS) that prevents users from accessing web content. Organizations using affected versions should upgrade to the latest patched releases to ensure service availability.

Technical details

The vulnerability consists of a use-after-free (CWE-416) and a time-of-check/time-of-use (TOCTOU) race condition within the remap configuration handling component of Apache Traffic Server. These flaws occur when the server processes or reloads remap rules, potentially allowing an attacker to trigger memory corruption or an invalid memory access. The attack can be initiated over the network without authentication, primarily resulting in a high impact on service availability (Denial of Service). Patches have been released in versions 9.2.15 and 10.1.4.

Affected products

  • Apache Traffic Server 8.0.0 - 8.1.9, 9.0.0 - 9.2.14, 10.0.0 - 10.1.3

Timeline

  • 2026-07-29: disclosed
  • 2026-07-29: advisory

References