Description
The Apache Traffic Server header_rewrite plugin can crash or corrupt memory during cookie operations and CIDR condition matching.

This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3.

Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.
Published: 2026-07-29
Score: 8.3 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The header_rewrite plugin in Apache Traffic Server can corrupt memory during cookie operations and CIDR condition matching, resulting in an out-of-bounds write (CWE‑787). This flaw may cause the server to crash or lead to data corruption. Based on the description, the corruption occurs while processing user-supplied headers, so the flaw is triggered by crafted HTTP traffic.

Affected Systems

The affected versions are Apache Traffic Server 8.0.0 through 8.1.9, 9.0.0 through 9.2.14, and 10.0.0 through 10.1.3. Users should verify whether their installation, including any custom or downstream distributions, includes the necessary patch before proceeding.

Risk and Exploitability

The CVSS score of 8.3 indicates high severity, while an EPSS score of less than 1% suggests that large‑scale exploitation is currently unlikely. The vulnerability is not listed in CISA KEV. The likely attack vector is through malicious HTTP requests that contain malformed cookie headers or CIDR conditions; the attacker requires network access to the Traffic Server instance. Although no public exploit has been documented, the potential for an out‑of‑bounds write means that, in theory, an attacker could attempt to leverage this flaw for arbitrary code execution, but such exploitation is not confirmed by the supplied data.

Generated by OpenCVE AI on August 3, 2026 at 13:35 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Apache Traffic Server to at least 9.2.15 or 10.1.4, which contain the memory‑corruption fix.
  • If upgrading immediately is not possible, disable or remove the header_rewrite plugin for all inbound traffic until a patched version is deployed.
  • Monitor server logs for unusual crashes or memory corruption indicators, and review access controls for user‑supplied headers.

Generated by OpenCVE AI on August 3, 2026 at 13:35 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 29 Jul 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 29 Jul 2026 11:30:00 +0000

Type Values Removed Values Added
First Time appeared Apache
Apache traffic Server
Vendors & Products Apache
Apache traffic Server

Wed, 29 Jul 2026 09:30:00 +0000

Type Values Removed Values Added
Description The Apache Traffic Server header_rewrite plugin can crash or corrupt memory during cookie operations and CIDR condition matching. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.
Title Apache Traffic Server: header_rewrite plugin cookie handling can corrupt memory
Weaknesses CWE-787
References
Metrics cvssV3_1

{'score': 8.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H'}

cvssV4_0

{'score': 8.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Apache Traffic Server
cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published:

Updated: 2026-07-29T12:13:32.044Z

Reserved: 2026-06-29T16:28:43.256Z

Link: CVE-2026-58184

cve-icon Vulnrichment

Updated: 2026-07-29T12:13:27.279Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-29T10:16:43.520

Modified: 2026-07-31T20:52:52.623

Link: CVE-2026-58184

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T13:45:03Z

Weaknesses