Junglewise Threat Intelligence

CVE-2026-58180: Apache Traffic Server stack overflow in txn_box plugin

CVE-2026-58180 · Severity: high · CVSS 7.5 · Published 2026-07-29

Technologies: Apache Traffic Server. Vendors: Apache.

Executive brief

Apache Traffic Server, a high-performance web proxy and caching server, contains a vulnerability in its txn_box plugin. An attacker can send specially crafted network traffic to trigger a system crash, leading to a denial-of-service. This disrupts the availability of web services and content delivery for users relying on the affected server.

Technical details

A stack-based buffer overflow (CWE-121) exists in the txn_box plugin of Apache Traffic Server. The vulnerability is triggered when the plugin processes attacker-controlled input, leading to memory corruption and a subsequent crash of the service. This is a network-reachable vulnerability that requires no authentication or user interaction. Successful exploitation results in a complete loss of availability (Denial of Service). The issue is resolved in versions 9.2.15 and 10.1.4.

Affected products

  • Apache Traffic Server 8.0.0 through 8.1.9, 9.0.0 through 9.2.14, 10.0.0 through 10.1.3

Timeline

  • 2026-07-29: advisory: Initial advisory published by Apache Software Foundation
  • 2026-07-29: disclosed: CVE-2026-58180 published to NVD

References

Related threats