Apache
Apache Traffic Server: vulnerabilities and CVEs
Apache Traffic Server has 121 published vulnerabilities, 41 of them in the last 12 months. 15 are rated critical and 1 are listed by CISA as actively exploited.
CVEs121
Last 12 months41
Critical15
Actively exploited1
All vulnerabilities in the catalogue →⭐ Follow this technology
🔴 Actively exploited (CISA KEV)
| CVE | Severity | EPSS | Active exploitation | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-44487 | High (7.5) | 100% | ⚠ Active exploitation | Oct 10, 2023 | The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023. |
Latest vulnerabilities
| CVE | Severity | EPSS | Active exploitation | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-65100 | Medium (6.3) | 0.58% | — | Jul 29, 2026 | Apache Traffic Server updates the HTTP/2 HPACK dynamic table before confirming the header block encoded successfully, so an encode failure leaves the encoder out of sync with the peer decoder and corrupts subsequent… |
| CVE-2026-58189 | High (8.2) | 0.63% | — | Jul 29, 2026 | Apache Traffic Server allows redirect-limit bypass when plugins reset the retry counter, enabling SSRF amplification. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from… |
| CVE-2026-58188 | High (8.4) | 0.77% | — | Jul 29, 2026 | Several Apache Traffic Server experimental plugins have memory-safety and limit-bypass errors. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3.… |
| CVE-2026-58187 | Medium (6.3) | 0.58% | — | Jul 29, 2026 | The Apache Traffic Server multiplexer plugin overruns its chunk-decode buffer on upstream input, enabling denial of service. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14,… |
| CVE-2026-58186 | High (8.2) | 0.70% | — | Jul 29, 2026 | The Apache Traffic Server webp_transform plugin can decode unsafely and serve mislabeled, cacheable responses. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0… |
| CVE-2026-58185 | High (8.2) | 0.58% | — | Jul 29, 2026 | The Apache Traffic Server intercept plugin has a use-after-free. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to… |
| CVE-2026-58184 | High (8.3) | 0.59% | — | Jul 29, 2026 | The Apache Traffic Server header_rewrite plugin can crash or corrupt memory during cookie operations and CIDR condition matching. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through… |
| CVE-2026-58183 | High (8.2) | 0.66% | — | Jul 29, 2026 | The Apache Traffic Server prefetch plugin can crash when processing attacker-influenced input. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3.… |
| CVE-2026-58182 | High (8.2) | 0.73% | — | Jul 29, 2026 | The Apache Traffic Server ts_lua plugin mishandles initialization, transform context, and per-instance state. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0… |
| CVE-2026-58181 | High (8.2) | 0.66% | — | Jul 29, 2026 | The Apache Traffic Server uri_signing and url_sig plugins can exhaust the stack or crash on attacker input. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0… |
| CVE-2026-58180 | High (8.2) | 0.66% | — | Jul 29, 2026 | The Apache Traffic Server txn_box plugin overflows the stack from attacker-controlled input. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3.… |
| CVE-2026-58179 | Critical (9.2) | 0.60% | — | Jul 29, 2026 | The Apache Traffic Server regex_remap plugin overflows the stack and integers from substitution input. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through… |
| CVE-2026-58178 | High (8.2) | 0.66% | — | Jul 29, 2026 | The Apache Traffic Server ESI plugin can recurse without bound and fetch attacker-controlled URLs. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through… |
| CVE-2026-58177 | High (8.3) | 0.59% | — | Jul 29, 2026 | The Apache Traffic Server Cripts framework has out-of-bounds writes, path traversal, and use-after-free errors. This issue affects Apache Traffic Server: from 10.0.0 through 10.1.3. Users are recommended to upgrade to… |
| CVE-2026-58175 | High (8.2) | 0.66% | — | Jul 29, 2026 | Apache Traffic Server leaks memory when handling HostDB SRV records. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to… |
| CVE-2026-58164 | High (8.3) | 0.66% | — | Jul 29, 2026 | Apache Traffic Server has use-after-free and time-of-check/time-of-use errors in remap configuration handling. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0… |
| CVE-2026-58163 | High (8.3) | 0.70% | — | Jul 29, 2026 | Apache Traffic Server mishandles on-disk cache fields and object lifetimes, corrupting state or crashing. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0… |
| CVE-2026-58162 | High (8.4) | 0.36% | — | Jul 29, 2026 | The Apache Traffic Server certifier plugin generates certificates based on attacker-controlled client SNI. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0… |
| CVE-2026-58161 | Critical (9.2) | 0.66% | — | Jul 29, 2026 | Apache Traffic Server can crash from null dereferences and dangling references in TLS and SNI handling. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through… |
| CVE-2026-58160 | Medium (6.3) | 0.58% | — | Jul 29, 2026 | Apache Traffic Server reads out of bounds while parsing DNS answers. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to… |
| CVE-2026-58159 | High (7) | 0.56% | — | Jul 29, 2026 | Apache Traffic Server can bypass IP access controls on UDS listeners and through ACL matching errors. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through… |
| CVE-2026-58158 | High (8.2) | 0.58% | — | Jul 29, 2026 | Apache Traffic Server mishandles PROXY protocol input, truncating ports and overflowing the stack. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through… |
| CVE-2026-58157 | Medium (6.9) | 0.48% | — | Jul 29, 2026 | Apache Traffic Server can reuse server sessions and tunnels improperly, exposing data across client connections. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0… |
| CVE-2026-65325 | Medium (6.3) | 0.28% | — | Jul 29, 2026 | Apache Traffic Server reuses multiplexed HTTP/2 origin connections without verifying the server certificate covers the new request hostname. This issue affects Apache Traffic Server: from 9.0.0 through 9.2.14, from… |
| CVE-2026-65324 | High (8.2) | 0.66% | — | Jul 29, 2026 | Apache Traffic Server drops the per-stream buffer cap when dechunking HTTP/2 or HTTP/3 responses, letting a slow client exhaust server memory. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from… |
| CVE-2026-58156 | Medium (6.3) | 0.39% | — | Jul 29, 2026 | Apache Traffic Server mis-parses ports in URLs and userinfo, allowing port-based access-control bypass. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through… |
| CVE-2026-58155 | Critical (9.2) | 0.54% | — | Jul 29, 2026 | Apache Traffic Server truncates over-long header names, allowing header aliasing, request smuggling, and policy bypass. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from… |
| CVE-2026-58154 | Critical (9.2) | 0.54% | — | Jul 29, 2026 | Apache Traffic Server can write out of bounds or overflow integers while parsing MIME and HTTP headers. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through… |
| CVE-2026-58153 | Medium (6.3) | 0.64% | — | Jul 29, 2026 | Apache Traffic Server forwards HTTP/2 origin trailers to HTTP/1 clients without proper chunked framing when converting HTTP/2 to HTTP/1. This issue affects Apache Traffic Server: from 10.0.0 through 10.1.3. Users are… |
| CVE-2026-58152 | Medium (6.9) | 0.58% | — | Jul 29, 2026 | Apache Traffic Server mishandles integers while decoding HPACK/XPACK headers, corrupting memory. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3.… |
🎯 How it gets exploited (ATT&CK techniques)
Number of CVEs of this technology mapped to each exploitation or primary-impact technique.