Description
The Apache Traffic Server Cripts framework has out-of-bounds writes, path traversal, and use-after-free errors.

This issue affects Apache Traffic Server: from 10.0.0 through 10.1.3.

Users are recommended to upgrade to version 10.1.4, which fix the issue.
Published: 2026-07-29
Score: 8.3 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Cripts framework in Apache Traffic Server contains out‑of‑bounds memory writes, path‑traversal, and use‑after‑free conditions that violate program memory safety. These flaws can be abused to corrupt process memory and potentially execute arbitrary code, compromising the confidentiality, integrity, and availability of the affected system. The weakness is classified as CWE‑787.

Affected Systems

Vendors affected are the Apache Software Foundation’s Apache Traffic Server, versions 10.0.0 through 10.1.3. Any deployment running one of these releases is vulnerable unless upgraded.

Risk and Exploitability

The CVSS score of 8.3 indicates high severity, and the EPSS score of less than 1% suggests a low current likelihood of exploitation. It is not listed in CISA KEV. The likely attack vector is remote exploitation via the Traffic Server service, although the description does not explicitly state whether local or remote access is required. Exploitation would require reaching the vulnerable Cripts framework component.

Generated by OpenCVE AI on August 3, 2026 at 13:38 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Apache Traffic Server to version 10.1.4 or later.
  • Restart or reload the Traffic Server service so that the patched binaries are in use.
  • If an immediate upgrade is not possible, restrict network access to the Traffic Server instance to a trusted set of hosts to reduce exposure.

Generated by OpenCVE AI on August 3, 2026 at 13:38 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 29 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 29 Jul 2026 11:45:00 +0000

Type Values Removed Values Added
First Time appeared Apache
Apache traffic Server
Vendors & Products Apache
Apache traffic Server

Wed, 29 Jul 2026 09:30:00 +0000

Type Values Removed Values Added
Description The Apache Traffic Server Cripts framework has out-of-bounds writes, path traversal, and use-after-free errors. This issue affects Apache Traffic Server: from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 10.1.4, which fix the issue.
Title Apache Traffic Server: Memory-safety and path-traversal errors in the Cripts framework
Weaknesses CWE-787
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:H'}

cvssV4_0

{'score': 8.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:H/SC:L/SI:L/SA:N'}


Subscriptions

Apache Traffic Server
cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published:

Updated: 2026-07-29T13:33:06.611Z

Reserved: 2026-06-29T16:24:10.975Z

Link: CVE-2026-58177

cve-icon Vulnrichment

Updated: 2026-07-29T13:33:00.832Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-29T10:16:42.510

Modified: 2026-07-31T20:54:52.427

Link: CVE-2026-58177

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T13:45:03Z

Weaknesses