Junglewise Threat Intelligence

CVE-2026-58183: Apache Traffic Server denial of service in prefetch plugin

CVE-2026-58183 · Severity: medium · CVSS 5.9 · Published 2026-07-29

Technologies: Apache Traffic Server. Vendors: Apache.

Executive brief

Apache Traffic Server, a high-performance caching proxy used to speed up web content delivery, contains a vulnerability in its prefetch plugin. An attacker can send specially crafted input that causes the plugin to crash, potentially leading to a denial-of-service condition. This could disrupt website availability and impact user experience by slowing down content delivery. Organizations using the affected versions should upgrade to the latest patched releases to ensure service stability.

Technical details

A vulnerability exists in the prefetch plugin of Apache Traffic Server due to improper input validation (CWE-20). An unauthenticated remote attacker can provide malicious input that triggers a crash in the plugin, resulting in a denial-of-service (DoS) for the affected service. The attack vector is network-based, though the CVSS assessment suggests a high complexity (AC:H), likely due to specific configuration requirements or timing needed to trigger the prefetch logic. The issue is resolved in versions 9.2.15 and 10.1.4.

Affected products

  • Apache Traffic Server 8.0.0 through 8.1.9, 9.0.0 through 9.2.14, 10.0.0 through 10.1.3

Timeline

  • 2026-07-29: disclosed
  • 2026-07-29: advisory
  • 2026-07-29: patched

References

Related threats