Description
The Apache Traffic Server prefetch plugin can crash when processing attacker-influenced input.

This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3.

Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.
Published: 2026-07-29
Score: 8.2 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The prefetch plugin in Apache Traffic Server is vulnerable to a crash when it processes input that an attacker can influence. This flaw is an input validation error, which can cause the server to terminate unexpectedly, leading to a denial of service for legitimate users.

Affected Systems

Apache Traffic Server from version 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, and from 10.0.0 through 10.1.3.

Risk and Exploitability

The CVSS score of 8.2 indicates a high severity, but the EPSS score is below 1%, suggesting a low probability of exploitation at present. The vulnerability is not listed in CISA’s KEV catalog. Based on the description, it is inferred that the crash can be triggered over the network by sending crafted requests to the prefetch plugin. Accordingly, the likely attack vector is remote, originating from an external client or an internal adversary with network access.

Generated by OpenCVE AI on August 4, 2026 at 12:34 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to Apache Traffic Server 9.2.15 or 10.1.4, which contains the fix.
  • If an upgrade is not immediately possible, disable or remove the prefetch plugin from the configuration to prevent execution of the vulnerable code.
  • Restrict network access to the Traffic Server instance using firewall rules or access control lists to limit exposure to trusted networks.

Generated by OpenCVE AI on August 4, 2026 at 12:34 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 30 Jul 2026 15:45:00 +0000

Type Values Removed Values Added
First Time appeared Apache
Apache traffic Server
Vendors & Products Apache
Apache traffic Server

Wed, 29 Jul 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 29 Jul 2026 09:30:00 +0000

Type Values Removed Values Added
Description The Apache Traffic Server prefetch plugin can crash when processing attacker-influenced input. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.
Title Apache Traffic Server: prefetch plugin can crash on attacker-influenced input
Weaknesses CWE-20
References
Metrics cvssV3_1

{'score': 5.9, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H'}

cvssV4_0

{'score': 8.2, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Apache Traffic Server
cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published:

Updated: 2026-07-29T12:13:54.210Z

Reserved: 2026-06-29T16:28:06.552Z

Link: CVE-2026-58183

cve-icon Vulnrichment

Updated: 2026-07-29T12:13:50.650Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-29T10:16:43.373

Modified: 2026-07-31T20:53:07.187

Link: CVE-2026-58183

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T12:45:05Z

Weaknesses
  • CWE-20

    Improper Input Validation