Executive brief
Apache Traffic Server, a high-performance caching proxy used to speed up web content delivery, contains a vulnerability in its URL signing plugins. An attacker can send specially crafted requests that cause the server to crash or stop responding. This could lead to a service outage, preventing users from accessing websites or applications served through the proxy.
Technical details
A stack-based buffer overflow (CWE-121) exists in the uri_signing and url_sig plugins of Apache Traffic Server. The vulnerability is triggered by specific attacker-controlled input that leads to stack exhaustion or a process crash. This is a remote, unauthenticated attack vector that impacts service availability (Denial of Service). The issue affects versions 8.x, 9.x, and 10.x up to 10.1.3. Users are advised to upgrade to versions 9.2.15 or 10.1.4 to mitigate this risk.
Affected products
- Apache Traffic Server 8.0.0 through 8.1.9, 9.0.0 through 9.2.14, 10.0.0 through 10.1.3
Timeline
- 2026-07-29: disclosed
- 2026-07-29: advisory