Apache
Apache Traffic Server: vulnerabilidades y CVE
Apache Traffic Server tiene 121 vulnerabilidades publicadas, 41 de ellas en los últimos 12 meses. 15 son críticas y 1 figuran en el catálogo de explotación activa de CISA.
CVE121
Últimos 12 meses41
Críticas15
Explotadas activamente1
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
🔴 Explotadas activamente (CISA KEV)
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2023-44487 | Alta (7.5) | 100% | ⚠ Explotación activa | 10 oct 2023 | The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023. |
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-58177 | Alta (8.3) | 0.59% | — | 29 jul 2026 | The Apache Traffic Server Cripts framework has out-of-bounds writes, path traversal, and use-after-free errors. This issue affects Apache Traffic Server: from 10.0.0 through 10.1.3. Users are recommended to upgrade to… |
| CVE-2026-65325 | Media (6.3) | 0.28% | — | 29 jul 2026 | Apache Traffic Server reuses multiplexed HTTP/2 origin connections without verifying the server certificate covers the new request hostname. This issue affects Apache Traffic Server: from 9.0.0 through 9.2.14, from… |
| CVE-2026-58153 | Media (6.3) | 0.64% | — | 29 jul 2026 | Apache Traffic Server forwards HTTP/2 origin trailers to HTTP/1 clients without proper chunked framing when converting HTTP/2 to HTTP/1. This issue affects Apache Traffic Server: from 10.0.0 through 10.1.3. Users are… |
| CVE-2026-65100 | Media (6.3) | 0.58% | — | 29 jul 2026 | Apache Traffic Server updates the HTTP/2 HPACK dynamic table before confirming the header block encoded successfully, so an encode failure leaves the encoder out of sync with the peer decoder and corrupts subsequent… |
| CVE-2026-58189 | Alta (8.2) | 0.63% | — | 29 jul 2026 | Apache Traffic Server allows redirect-limit bypass when plugins reset the retry counter, enabling SSRF amplification. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.11, from 9.0.0 through 9.2.14, from… |
| CVE-2026-58188 | Alta (8.4) | 0.77% | — | 29 jul 2026 | Several Apache Traffic Server experimental plugins have memory-safety and limit-bypass errors. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.11, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3.… |
| CVE-2026-58187 | Media (6.3) | 0.58% | — | 29 jul 2026 | The Apache Traffic Server multiplexer plugin overruns its chunk-decode buffer on upstream input, enabling denial of service. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.11, from 9.0.0 through… |
| CVE-2026-58186 | Alta (8.2) | 0.70% | — | 29 jul 2026 | The Apache Traffic Server webp_transform plugin can decode unsafely and serve mislabeled, cacheable responses. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.11, from 9.0.0 through 9.2.14, from 10.0.0… |
| CVE-2026-58185 | Alta (8.2) | 0.58% | — | 29 jul 2026 | The Apache Traffic Server intercept plugin has a use-after-free. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.11, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to… |
| CVE-2026-58184 | Alta (8.3) | 0.59% | — | 29 jul 2026 | The Apache Traffic Server header_rewrite plugin can crash or corrupt memory during cookie operations and CIDR condition matching. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.11, from 9.0.0 through… |
| CVE-2026-58183 | Alta (8.2) | 0.66% | — | 29 jul 2026 | The Apache Traffic Server prefetch plugin can crash when processing attacker-influenced input. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.11, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3.… |
| CVE-2026-58182 | Alta (8.2) | 0.73% | — | 29 jul 2026 | The Apache Traffic Server ts_lua plugin mishandles initialization, transform context, and per-instance state. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.11, from 9.0.0 through 9.2.14, from 10.0.0… |
| CVE-2026-58181 | Alta (8.2) | 0.66% | — | 29 jul 2026 | The Apache Traffic Server uri_signing and url_sig plugins can exhaust the stack or crash on attacker input. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.11, from 9.0.0 through 9.2.14, from 10.0.0… |
| CVE-2026-58180 | Alta (8.2) | 0.66% | — | 29 jul 2026 | The Apache Traffic Server txn_box plugin overflows the stack from attacker-controlled input. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.11, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3.… |
| CVE-2026-58179 | Crítica (9.2) | 0.60% | — | 29 jul 2026 | The Apache Traffic Server regex_remap plugin overflows the stack and integers from substitution input. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.11, from 9.0.0 through 9.2.14, from 10.0.0 through… |
| CVE-2026-58178 | Alta (8.2) | 0.66% | — | 29 jul 2026 | The Apache Traffic Server ESI plugin can recurse without bound and fetch attacker-controlled URLs. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.11, from 9.0.0 through 9.2.14, from 10.0.0 through… |
| CVE-2026-58175 | Alta (8.2) | 0.66% | — | 29 jul 2026 | Apache Traffic Server leaks memory when handling HostDB SRV records. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.11, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to… |
| CVE-2026-58164 | Alta (8.3) | 0.66% | — | 29 jul 2026 | Apache Traffic Server has use-after-free and time-of-check/time-of-use errors in remap configuration handling. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.11, from 9.0.0 through 9.2.14, from 10.0.0… |
| CVE-2026-58163 | Alta (8.3) | 0.70% | — | 29 jul 2026 | Apache Traffic Server mishandles on-disk cache fields and object lifetimes, corrupting state or crashing. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.11, from 9.0.0 through 9.2.14, from 10.0.0… |
| CVE-2026-58162 | Alta (8.4) | 0.36% | — | 29 jul 2026 | The Apache Traffic Server certifier plugin generates certificates based on attacker-controlled client SNI. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.11, from 9.0.0 through 9.2.14, from 10.0.0… |
| CVE-2026-58161 | Crítica (9.2) | 0.66% | — | 29 jul 2026 | Apache Traffic Server can crash from null dereferences and dangling references in TLS and SNI handling. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.11, from 9.0.0 through 9.2.14, from 10.0.0 through… |
| CVE-2026-58160 | Media (6.3) | 0.58% | — | 29 jul 2026 | Apache Traffic Server reads out of bounds while parsing DNS answers. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.11, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to… |
| CVE-2026-58159 | Alta (7) | 0.56% | — | 29 jul 2026 | Apache Traffic Server can bypass IP access controls on UDS listeners and through ACL matching errors. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.11, from 9.0.0 through 9.2.14, from 10.0.0 through… |
| CVE-2026-58158 | Alta (8.2) | 0.58% | — | 29 jul 2026 | Apache Traffic Server mishandles PROXY protocol input, truncating ports and overflowing the stack. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.11, from 9.0.0 through 9.2.14, from 10.0.0 through… |
| CVE-2026-58157 | Media (6.9) | 0.48% | — | 29 jul 2026 | Apache Traffic Server can reuse server sessions and tunnels improperly, exposing data across client connections. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.11, from 9.0.0 through 9.2.14, from… |
| CVE-2026-41920 | Alta (7) | 0.53% | — | 29 jul 2026 | Improper Access Control vulnerability in Apache Traffic Server. This issue affects Apache Traffic Server: from 9.0.0 through 9.1.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.1.15 or… |
| CVE-2026-33267 | Alta (7.7) | 0.60% | — | 29 jul 2026 | Improper Input Validation vulnerability in Apache Traffic Server. This issue affects Apache Traffic Server: from 9.2.0 through 9.2.14, from 10.1.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or… |
| CVE-2026-24033 | Media (6.9) | 0.57% | — | 29 jul 2026 | Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') vulnerability in Apache Traffic Server. This issue affects Apache Traffic Server: from 10.0.0 through 10.1.3, from 9.0.0 through 9.2.14.… |
| CVE-2026-22068 | Media (6.9) | 0.61% | — | 29 jul 2026 | Regular Expression without Anchors vulnerability in Apache Traffic Server. This issue affects Apache Traffic Server: from 10.0.X through 10.1.3, from 9.0.X through 9.2.14. Users are recommended to upgrade to version… |
| CVE-2026-65324 | Alta (8.2) | 0.66% | — | 29 jul 2026 | Apache Traffic Server drops the per-stream buffer cap when dechunking HTTP/2 or HTTP/3 responses, letting a slow client exhaust server memory. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.11, from… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.