Executive brief
Apache Traffic Server, a high-performance caching proxy used to manage web traffic, contains a vulnerability in its regex_remap plugin. This plugin is responsible for rewriting URLs based on specific patterns. An attacker could exploit this flaw to cause a system crash or potentially gain unauthorized control over the server, impacting the availability and security of the network traffic being managed.
Technical details
A stack-based buffer overflow and integer overflow vulnerability exists in the regex_remap plugin of Apache Traffic Server. The flaw is triggered by malicious substitution input during URL remapping operations. An unauthenticated remote attacker can exploit this by sending specially crafted requests that trigger the remapping logic, potentially leading to arbitrary code execution or a denial-of-service (DoS) condition. The vulnerability affects versions 8.x, 9.x, and 10.x up to 10.1.3. Users are advised to upgrade to versions 9.2.15 or 10.1.4.
Affected products
- Apache Traffic Server 8.0.0 through 8.1.9, 9.0.0 through 9.2.14, 10.0.0 through 10.1.3
Timeline
- 2026-07-29: disclosed
- 2026-07-29: advisory