Description
The Apache Traffic Server multiplexer plugin overruns its chunk-decode buffer on upstream input, enabling denial of service.

This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3.

Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.
Published: 2026-07-29
Score: 6.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability lies in a buffer overrun within the chunk decoder of the multiplexer plugin in Apache Traffic Server. An attacker can feed oversize upstream data that causes the decoder to write beyond its allocated buffer, leading to a crash or unresponsive state. This flaw is a classic out‑of‑bounds write (CWE‑787) that compromises the availability of the server process.

Affected Systems

Apache Traffic Server versions 8.0.0‑8.1.9, 9.0.0‑9.2.14, and 10.0.0‑10.1.3 are affected. The issue arises when the multiplexer plugin is active; upgrading to 9.2.15 or 10.1.4 removes the bug.

Risk and Exploitability

The CVSS score of 6.3 indicates a medium severity, and the EPSS score of less than 1% suggests that exploitation is unlikely to be widespread. The vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is via network traffic from upstream proxies or clients that can send arbitrary sized chunks to the server, bypassing any size limits. The flaw can cause an abrupt termination of the Traffic Server process, leading to downtime until a restart or reload occurs.

Generated by OpenCVE AI on August 3, 2026 at 13:34 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Apache Traffic Server to version 9.2.15 or 10.1.4, the latest releases that contain the security fix.
  • Disable or remove the multiplexer plugin if it is not required for your deployment, thereby eliminating the attack surface.
  • After updating or disabling the plugin, restart or reload the Traffic Server service and monitor for abnormal crashes or performance degradation.

Generated by OpenCVE AI on August 3, 2026 at 13:34 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 30 Jul 2026 22:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 29 Jul 2026 12:00:00 +0000

Type Values Removed Values Added
First Time appeared Apache
Apache apache Traffic Server
Vendors & Products Apache
Apache apache Traffic Server

Wed, 29 Jul 2026 09:30:00 +0000

Type Values Removed Values Added
Description The Apache Traffic Server multiplexer plugin overruns its chunk-decode buffer on upstream input, enabling denial of service. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.
Title Apache Traffic Server: Multiplexer plugin chunk decoder enables a denial of service
Weaknesses CWE-787
References
Metrics cvssV3_1

{'score': 3.7, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L'}

cvssV4_0

{'score': 6.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N'}


Subscriptions

Apache Apache Traffic Server Traffic Server
cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published:

Updated: 2026-07-29T12:11:35.420Z

Reserved: 2026-06-29T16:35:39.110Z

Link: CVE-2026-58187

cve-icon Vulnrichment

Updated: 2026-07-29T12:11:31.478Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-29T10:16:43.950

Modified: 2026-07-31T20:51:17.980

Link: CVE-2026-58187

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T13:45:03Z

Weaknesses