CVE-2026-102795
- EPSS 0.28%
- Veröffentlicht 02.10.2026 17:40:50
- Zuletzt bearbeitet 02.10.2026 19:16:39
Improper Access Control vulnerability in Apache Traffic Server. This issue affects Apache Traffic Server: from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fixes the issue...
CVE-2026-65100
- EPSS 0.45%
- Veröffentlicht 29.07.2026 09:06:17
- Zuletzt bearbeitet 01.10.2026 18:17:26
Apache Traffic Server updates the HTTP/2 HPACK dynamic table before confirming the header block encoded successfully, so an encode failure leaves the encoder out of sync with the peer decoder and corrupts subsequent header blocks on the connection. ...
CVE-2026-58189
- EPSS 0.49%
- Veröffentlicht 29.07.2026 09:05:19
- Zuletzt bearbeitet 01.10.2026 18:17:26
Apache Traffic Server allows redirect-limit bypass when plugins reset the retry counter, enabling SSRF amplification. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.11, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Us...
CVE-2026-58188
- EPSS 0.6%
- Veröffentlicht 29.07.2026 09:04:24
- Zuletzt bearbeitet 01.10.2026 18:17:26
Several Apache Traffic Server experimental plugins have memory-safety and limit-bypass errors. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.11, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to ...
CVE-2026-58187
- EPSS 0.45%
- Veröffentlicht 29.07.2026 09:03:22
- Zuletzt bearbeitet 01.10.2026 18:17:26
The Apache Traffic Server multiplexer plugin overruns its chunk-decode buffer on upstream input, enabling denial of service. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.11, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3...
CVE-2026-58186
- EPSS 0.55%
- Veröffentlicht 29.07.2026 09:01:39
- Zuletzt bearbeitet 01.10.2026 18:17:26
The Apache Traffic Server webp_transform plugin can decode unsafely and serve mislabeled, cacheable responses. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.11, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are...
CVE-2026-58185
- EPSS 0.45%
- Veröffentlicht 29.07.2026 08:57:48
- Zuletzt bearbeitet 01.10.2026 18:17:26
The Apache Traffic Server intercept plugin has a use-after-free. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.11, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 1...
CVE-2026-58184
- EPSS 0.46%
- Veröffentlicht 29.07.2026 08:56:51
- Zuletzt bearbeitet 01.10.2026 18:17:25
The Apache Traffic Server header_rewrite plugin can crash or corrupt memory during cookie operations and CIDR condition matching. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.11, from 9.0.0 through 9.2.14, from 10.0.0 through 1...
CVE-2026-58183
- EPSS 0.51%
- Veröffentlicht 29.07.2026 08:55:52
- Zuletzt bearbeitet 01.10.2026 18:17:25
The Apache Traffic Server prefetch plugin can crash when processing attacker-influenced input. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.11, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to ...
CVE-2026-58182
- EPSS 0.54%
- Veröffentlicht 29.07.2026 08:54:49
- Zuletzt bearbeitet 01.10.2026 18:17:25
The Apache Traffic Server ts_lua plugin mishandles initialization, transform context, and per-instance state. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.11, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are ...