CVE-2026-58159
- EPSS 0.53%
- Veröffentlicht 29.07.2026 08:32:04
- Zuletzt bearbeitet 03.08.2026 19:36:49
Apache Traffic Server can bypass IP access controls on UDS listeners and through ACL matching errors. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended t...
CVE-2026-58158
- EPSS 0.56%
- Veröffentlicht 29.07.2026 08:26:32
- Zuletzt bearbeitet 03.08.2026 19:38:13
Apache Traffic Server mishandles PROXY protocol input, truncating ports and overflowing the stack. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to u...
CVE-2026-58157
- EPSS 0.45%
- Veröffentlicht 29.07.2026 08:25:52
- Zuletzt bearbeitet 03.08.2026 19:50:55
Apache Traffic Server can reuse server sessions and tunnels improperly, exposing data across client connections. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are re...
CVE-2026-58156
- EPSS 0.22%
- Veröffentlicht 29.07.2026 08:25:12
- Zuletzt bearbeitet 03.08.2026 13:40:10
Apache Traffic Server mis-parses ports in URLs and userinfo, allowing port-based access-control bypass. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended...
CVE-2026-58155
- EPSS 0.39%
- Veröffentlicht 29.07.2026 08:24:37
- Zuletzt bearbeitet 03.08.2026 13:40:19
Apache Traffic Server truncates over-long header names, allowing header aliasing, request smuggling, and policy bypass. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users...
CVE-2026-58154
- EPSS 0.37%
- Veröffentlicht 29.07.2026 08:24:02
- Zuletzt bearbeitet 03.08.2026 13:40:26
Apache Traffic Server can write out of bounds or overflow integers while parsing MIME and HTTP headers. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended...
CVE-2026-65325
- EPSS 0.17%
- Veröffentlicht 29.07.2026 08:23:28
- Zuletzt bearbeitet 03.08.2026 13:39:52
Apache Traffic Server reuses multiplexed HTTP/2 origin connections without verifying the server certificate covers the new request hostname. This issue affects Apache Traffic Server: from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are ...
CVE-2026-65324
- EPSS 0.47%
- Veröffentlicht 29.07.2026 08:17:46
- Zuletzt bearbeitet 03.08.2026 13:40:01
Apache Traffic Server drops the per-stream buffer cap when dechunking HTTP/2 or HTTP/3 responses, letting a slow client exhaust server memory. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0...
CVE-2026-58153
- EPSS 0.47%
- Veröffentlicht 29.07.2026 08:17:11
- Zuletzt bearbeitet 03.08.2026 13:41:54
Apache Traffic Server forwards HTTP/2 origin trailers to HTTP/1 clients without proper chunked framing when converting HTTP/2 to HTTP/1. This issue affects Apache Traffic Server: from 10.0.0 through 10.1.3. Users are recommended to upgrade to versi...
CVE-2026-58152
- EPSS 0.32%
- Veröffentlicht 29.07.2026 08:16:21
- Zuletzt bearbeitet 03.08.2026 13:42:08
Apache Traffic Server mishandles integers while decoding HPACK/XPACK headers, corrupting memory. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upg...