Description
Apache Traffic Server has use-after-free and time-of-check/time-of-use errors in remap configuration handling.

This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3.

Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.
Published: 2026-07-29
Score: 8.3 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Apache Traffic Server has a use‑after‑free bug combined with a time‑of‑check/time‑of‑use error in the handling of remap configuration files. The flaw causes the server to free memory that is still in use, leading to memory corruption. The weakness is classified as CWE‑416 and can undermine confidentiality, integrity, or availability of the affected system.

Affected Systems

The vulnerability affects Apache Software Foundation’s Apache Traffic Server. Versions 8.0.0 through 8.1.9, 9.0.0 through 9.2.14, and 10.0.0 through 10.1.3 are all susceptible.

Risk and Exploitability

The CVSS score of 8.3 indicates high severity, while the EPSS score of less than 1 % suggests exploitation probability is low under current conditions. The flaw is not listed in the CISA KEV catalog. The likely attack vector is inferred: an adversary that can supply or modify a remap configuration file—for example, through local access or via a network interface that allows configuration updates—could trigger the use‑after‑free and cause a crash or denial of service.

Generated by OpenCVE AI on August 4, 2026 at 23:14 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Apache Traffic Server to version 9.2.15 or later, or to 10.1.4 or later, to apply the fix for the use‑after‑free and TOCTOU errors.
  • Restrict write access to remap configuration files to privileged users only and monitor the configuration directory for unauthorized changes to reduce the risk of an attacker tampering with configuration entries.
  • If an immediate upgrade is not feasible, isolate the server so that remap configuration changes can only be performed by trusted administrators and consider disabling remap features until the server can be updated to a fixed release.

Generated by OpenCVE AI on August 4, 2026 at 23:14 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 29 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 29 Jul 2026 10:45:00 +0000

Type Values Removed Values Added
First Time appeared Apache
Apache traffic Server
Vendors & Products Apache
Apache traffic Server

Wed, 29 Jul 2026 09:30:00 +0000

Type Values Removed Values Added
Description Apache Traffic Server has use-after-free and time-of-check/time-of-use errors in remap configuration handling. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.
Title Apache Traffic Server: Remap configuration lifetime and TOCTOU errors cause use-after-free
Weaknesses CWE-416
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}

cvssV4_0

{'score': 8.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Apache Traffic Server
cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published:

Updated: 2026-07-29T13:39:55.405Z

Reserved: 2026-06-29T15:52:27.090Z

Link: CVE-2026-58164

cve-icon Vulnrichment

Updated: 2026-07-29T13:39:45.340Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-29T10:16:42.217

Modified: 2026-08-03T19:32:31.790

Link: CVE-2026-58164

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T23:15:07Z

Weaknesses