CVE-2026-58161
Apache Traffic Server is vulnerable to crashes caused by null dereferences and dangling references in TLS and SNI handling. The flaw can cause the server to crash, potentially leading to denial of service. Affected versions include 8.0.0 through 8.1.9, 9.0.0 through 9.2.14, and 10.0.0 through 10.1.3.
An official fix is available, so this entry is kept for 30 days and then removed automatically.
Who is affected
Apache Traffic Server versions 8.0.0–8.1.9, 9.0.0–9.2.14, and 10.0.0–10.1.3 users.
Real-world impact
An attacker could cause the server to crash, resulting in a denial of service that disrupts traffic for users relying on the server.
Why this severity
The CVSS score of 9.2 reflects the high impact of a crash (availability loss) combined with low attack complexity and no user interaction, making it a critical vulnerability.
What to do about it
- 01Upgrade Apache Traffic Server to version 9.2.15 or later, or to 10.1.4 or later.
- 02Restart the Traffic Server service to apply the update.
NVD-referenced vendor advisory
Timeline
- Jul 29, 2026 · 1d agoPublishedDisclosed and added to the National Vulnerability Database.
- Jul 29, 2026 · 1d agoOfficial fix availableA vendor patch or mitigation now exists — see the remediation steps above.