Executive brief
Apache Traffic Server, a high-performance web proxy and caching server, contains a vulnerability in its txn_box plugin. An attacker can send specially crafted network traffic to trigger a system crash, leading to a denial-of-service. This disrupts the availability of web services and content delivery for users relying on the affected server.
Technical details
A stack-based buffer overflow (CWE-121) exists in the txn_box plugin of Apache Traffic Server. The vulnerability is triggered when the plugin processes attacker-controlled input, leading to memory corruption and a subsequent crash of the service. This is a network-reachable vulnerability that requires no authentication or user interaction. Successful exploitation results in a complete loss of availability (Denial of Service). The issue is resolved in versions 9.2.15 and 10.1.4.
Affected products
- Apache Traffic Server 8.0.0 through 8.1.9, 9.0.0 through 9.2.14, 10.0.0 through 10.1.3
Timeline
- 2026-07-29: advisory: Initial advisory published by Apache Software Foundation
- 2026-07-29: disclosed: CVE-2026-58180 published to NVD