CVE-2026-58181
- EPSS 0.49%
- Veröffentlicht 29.07.2026 08:46:04
- Zuletzt bearbeitet 01.10.2026 18:17:25
The Apache Traffic Server uri_signing and url_sig plugins can exhaust the stack or crash on attacker input. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.11, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are re...
CVE-2026-58180
- EPSS 0.64%
- Veröffentlicht 29.07.2026 08:45:15
- Zuletzt bearbeitet 01.10.2026 18:17:25
The Apache Traffic Server txn_box plugin overflows the stack from attacker-controlled input. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.11, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to up...
CVE-2026-58179
- EPSS 0.55%
- Veröffentlicht 29.07.2026 08:44:33
- Zuletzt bearbeitet 01.10.2026 18:17:25
The Apache Traffic Server regex_remap plugin overflows the stack and integers from substitution input. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.11, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recomme...
CVE-2026-58178
- EPSS 0.64%
- Veröffentlicht 29.07.2026 08:43:25
- Zuletzt bearbeitet 01.10.2026 18:17:24
The Apache Traffic Server ESI plugin can recurse without bound and fetch attacker-controlled URLs. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.11, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended...
CVE-2026-58177
- EPSS 0.55%
- Veröffentlicht 29.07.2026 08:42:41
- Zuletzt bearbeitet 31.07.2026 20:54:52
The Apache Traffic Server Cripts framework has out-of-bounds writes, path traversal, and use-after-free errors. This issue affects Apache Traffic Server: from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 10.1.4, which fix the ...
CVE-2026-58175
- EPSS 0.64%
- Veröffentlicht 29.07.2026 08:41:50
- Zuletzt bearbeitet 01.10.2026 18:17:24
Apache Traffic Server leaks memory when handling HostDB SRV records. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.11, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 ...
CVE-2026-58164
- EPSS 0.64%
- Veröffentlicht 29.07.2026 08:37:42
- Zuletzt bearbeitet 01.10.2026 18:17:24
Apache Traffic Server has use-after-free and time-of-check/time-of-use errors in remap configuration handling. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.11, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are...
CVE-2026-58163
- EPSS 0.65%
- Veröffentlicht 29.07.2026 08:36:57
- Zuletzt bearbeitet 01.10.2026 18:17:24
Apache Traffic Server mishandles on-disk cache fields and object lifetimes, corrupting state or crashing. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.11, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are reco...
- EPSS 0.33%
- Veröffentlicht 29.07.2026 08:36:17
- Zuletzt bearbeitet 01.10.2026 18:17:24
The Apache Traffic Server certifier plugin generates certificates based on attacker-controlled client SNI. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.11, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are rec...
CVE-2026-58161
- EPSS 0.64%
- Veröffentlicht 29.07.2026 08:35:39
- Zuletzt bearbeitet 01.10.2026 18:17:24
Apache Traffic Server can crash from null dereferences and dangling references in TLS and SNI handling. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.11, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recomm...