Junglewise Threat Intelligence

CVE-2026-58184: Apache Traffic Server memory corruption in header_rewrite plugin

CVE-2026-58184 · Severity: high · CVSS 8.2 · Published 2026-07-29

Technologies: Apache Traffic Server. Vendors: Apache.

Executive brief

Apache Traffic Server, a high-performance web proxy used to manage and speed up internet traffic, contains a flaw in its header modification plugin. An attacker could exploit this to crash the server or potentially corrupt its memory, leading to service outages and impacting the reliability of web operations. Organizations using this software should update to the latest versions to ensure continuous service availability.

Technical details

An out-of-bounds write vulnerability (CWE-787) exists in the header_rewrite plugin of Apache Traffic Server. The flaw is triggered during specific cookie operations and CIDR condition matching, potentially leading to memory corruption or a process crash. The vulnerability is reachable over the network without authentication. Successful exploitation primarily impacts service availability (DoS) but may also allow for limited information disclosure. Patches are available in versions 9.2.15 and 10.1.4.

Affected products

  • Apache Traffic Server 8.0.0 through 8.1.9, 9.0.0 through 9.2.14, 10.0.0 through 10.1.3

Timeline

  • 2026-07-29: disclosed
  • 2026-07-29: advisory

References

Related threats