Description
The Apache Traffic Server webp_transform plugin can decode unsafely and serve mislabeled, cacheable responses.

This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3.

Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.
Published: 2026-07-29
Score: 8.2 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The webp_transform plugin processes WebP images without adequate validation, which leads to unsafe decoding and the ability to serve cacheable responses with incorrectly labeled MIME types. This flaw, classified as CWE‑20, can cause clients to receive cached content that does not match the declared content type, potentially resulting in content spoofing or downstream confusion.

Affected Systems

Apache Traffic Server versions 8.0.0 through 8.1.9, 9.0.0 through 9.2.14, and 10.0.0 through 10.1.3 are affected. All builds in these series contain the vulnerable webp_transform plugin.

Risk and Exploitability

The CVSS score of 8.2 signals a high severity vulnerability. The EPSS score of less than 1% indicates that automated exploitation attempts are currently rare, and the issue is not listed in the CISA KEV catalog. An attacker with network access to a publicly exposed Traffic Server instance could upload a malicious WebP file, causing the plugin to decode it unsafely and produce improperly labeled, cacheable responses. While the specific impact is mislabeling and potential cache poisoning, the possibility of further adverse effects would depend on additional contextual factors.

Generated by OpenCVE AI on August 4, 2026 at 12:33 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Apache Traffic Server to version 9.2.15 or 10.1.4, which contain the fix for the webp_transform plugin.
  • If an immediate upgrade is not possible, disable the webp_transform plugin by removing its entry from the server configuration to prevent unsafe decoding.
  • Apply network-level filtering to block or rate‑limit incoming WebP requests from untrusted sources as a temporary protective measure.

Generated by OpenCVE AI on August 4, 2026 at 12:33 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 29 Jul 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 29 Jul 2026 11:30:00 +0000

Type Values Removed Values Added
First Time appeared Apache
Apache traffic Server
Vendors & Products Apache
Apache traffic Server

Wed, 29 Jul 2026 09:30:00 +0000

Type Values Removed Values Added
Description The Apache Traffic Server webp_transform plugin can decode unsafely and serve mislabeled, cacheable responses. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.
Title Apache Traffic Server: webp_transform plugin decodes unsafely and mislabels degraded responses
Weaknesses CWE-20
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}

cvssV4_0

{'score': 8.2, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Apache Traffic Server
cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published:

Updated: 2026-07-29T12:11:57.125Z

Reserved: 2026-06-29T16:35:07.500Z

Link: CVE-2026-58186

cve-icon Vulnrichment

Updated: 2026-07-29T12:11:53.508Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-29T10:16:43.807

Modified: 2026-07-31T20:51:59.187

Link: CVE-2026-58186

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T12:45:05Z

Weaknesses
  • CWE-20

    Improper Input Validation