Junglewise Threat Intelligence

CVE-2026-58188: Apache Traffic Server memory safety and limit bypass in experimental plugins

CVE-2026-58188 · Severity: high · CVSS 8.2 · Published 2026-07-29

Technologies: Apache Traffic Server. Vendors: Apache.

Executive brief

Apache Traffic Server, a high-performance caching proxy used to manage web traffic, contains vulnerabilities in several of its experimental plugins. These flaws could allow an attacker to bypass security limits or cause the system to crash, potentially leading to service outages. Organizations using these specific plugins should update to the latest patched versions to ensure service availability and security.

Technical details

Apache Traffic Server experimental plugins are affected by memory-safety issues, specifically identified as out-of-bounds writes (CWE-787), and limit-bypass errors. These vulnerabilities can be triggered remotely over the network without authentication. Successful exploitation could lead to a denial-of-service (DoS) condition or allow an attacker to circumvent configured traffic limits. The issue impacts versions 8.x, 9.x, and 10.x; users are advised to upgrade to versions 9.2.15 or 10.1.4.

Affected products

  • Apache Traffic Server 8.0.0 to 8.1.9, 9.0.0 to 9.2.14, 10.0.0 to 10.1.3

Timeline

  • 2026-07-29: disclosed
  • 2026-07-29: advisory

References

Related threats