CVE-2026-58154
Apache Traffic Server can write out of bounds or overflow integers while parsing MIME and HTTP headers, which can cause serious problems. The issue affects several major releases of the software. Users should upgrade to a fixed version.
An official fix is available, so this entry is kept for 30 days and then removed automatically.
Who is affected
Apache Traffic Server versions 8.0.0 through 8.1.9, 9.0.0 through 9.2.14, and 10.0.0 through 10.1.3.
Real-world impact
An attacker could trigger a crash or potentially execute arbitrary code by sending specially crafted HTTP or MIME headers.
Why this severity
The CVSS score of 9.2 reflects the high impact of this vulnerability: it allows attackers to cause a denial of service or execute code with no authentication or user interaction, and it applies to many versions of the software.
What to do about it
- 01Check the current Apache Traffic Server version.
- 02Download and install Apache Traffic Server version 9.2.15 or later, or 10.1.4 or later.
- 03Restart the Apache Traffic Server service to apply the update.
NVD-referenced vendor advisory
Timeline
- Jul 29, 2026 · 1d agoPublishedDisclosed and added to the National Vulnerability Database.
- Jul 29, 2026 · 1d agoOfficial fix availableA vendor patch or mitigation now exists — see the remediation steps above.