Junglewise Threat Intelligence

CVE-2026-58177: Apache Traffic Server multiple vulnerabilities in Cripts framework

CVE-2026-58177 · Severity: high · CVSS 8.1 · Published 2026-07-29

Technologies: Apache Traffic Server. Vendors: Apache.

Executive brief

Apache Traffic Server, a high-performance caching proxy used to manage web traffic and deliver content, contains multiple memory safety and file handling vulnerabilities in its Cripts framework. These flaws could allow an attacker to disrupt service availability, access unauthorized files, or potentially execute malicious code. Organizations using affected versions should upgrade to version 10.1.4 to maintain the integrity and availability of their web delivery infrastructure.

Technical details

Apache Traffic Server (ATS) versions 10.0.0 through 10.1.3 are vulnerable to multiple memory corruption issues and a path traversal flaw within the Cripts framework. Specifically, the software contains out-of-bounds write (CWE-787) and use-after-free vulnerabilities, alongside path traversal errors. These vulnerabilities can be triggered over the network without authentication, though the CVSS vector suggests high complexity (AC:H), likely due to specific configuration or script requirements within the Cripts environment. Successful exploitation could lead to a denial-of-service (DoS) condition, unauthorized file access, or arbitrary code execution. The issues are resolved in Apache Traffic Server version 10.1.4.

Affected products

  • Apache Traffic Server 10.0.0 through 10.1.3

Timeline

  • 2026-07-29: advisory: Initial disclosure by Apache Software Foundation
  • 2026-07-29: patched: Version 10.1.4 released to address the vulnerabilities

References

Related threats