Description
The Apache Traffic Server ESI plugin can recurse without bound and fetch attacker-controlled URLs.

This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3.

Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.
Published: 2026-07-29
Score: 8.2 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Apache Traffic Server ESI plugin contains a flaw that lets user‑specified URLs trigger uncontrolled recursion, permitting the server to repeatedly request URLs under attacker control. This results in server‑side request forgery, enabling the attacker to make requests on the server’s behalf to any internal or external resource, and the unbounded recursion can exhaust server resources, leading to denial of service. The underlying weakness is identified as CWE‑674.

Affected Systems

The vulnerability affects Apache Traffic Server versions 8.0.0 to 8.1.9, 9.0.0 to 9.2.14, and 10.0.0 to 10.1.3. Users running any of these releases should upgrade to at least version 9.2.15 or 10.1.4, which contain the patch.

Risk and Exploitability

With a CVSS score of 8.2 the flaw is considered high severity. The EPSS score indicates that exploitation is currently unlikely, and it is not listed in CISA’s KEV catalog. Nevertheless, an attacker who can supply ESI content to the server could exploit the recursion flaw to force the traffic server to issue arbitrary HTTP requests (SSRF), and the infinite recursion may deplete CPU or memory, causing service interruption. The attack vector is likely remote, triggered by malformed or malicious ESI tags in HTTP responses.

Generated by OpenCVE AI on August 3, 2026 at 13:37 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Apache Traffic Server to version 9.2.15 or 10.1.4, which includes the fix for the ESI recursion flaw.
  • If an upgrade cannot be performed immediately, disable the ESI plugin to prevent recursive request processing until a patch is applied.
  • After disabling or patching, monitor server logs for signs of recursive requests or resource exhaustion to verify effective mitigation.

Generated by OpenCVE AI on August 3, 2026 at 13:37 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 29 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 29 Jul 2026 10:45:00 +0000

Type Values Removed Values Added
First Time appeared Apache
Apache apache Traffic Server
Vendors & Products Apache
Apache apache Traffic Server

Wed, 29 Jul 2026 09:30:00 +0000

Type Values Removed Values Added
Description The Apache Traffic Server ESI plugin can recurse without bound and fetch attacker-controlled URLs. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.
Title Apache Traffic Server: ESI plugin allows uncontrolled recursion and server-side request forgery
Weaknesses CWE-674
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}

cvssV4_0

{'score': 8.2, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Apache Apache Traffic Server Traffic Server
cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published:

Updated: 2026-07-29T13:30:21.898Z

Reserved: 2026-06-29T16:24:49.430Z

Link: CVE-2026-58178

cve-icon Vulnrichment

Updated: 2026-07-29T13:30:16.356Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-29T10:16:42.657

Modified: 2026-07-31T20:54:14.823

Link: CVE-2026-58178

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T13:45:03Z

Weaknesses