Description
Several Apache Traffic Server experimental plugins have memory-safety and limit-bypass errors.

This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3.

Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.
Published: 2026-07-29
Score: 8.4 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability involves memory‑safety and limit‑bypass flaws in several experimental plugins for Apache Traffic Server. These bugs fall under CWE‑787 and enable an attacker to perform out‑of‑bounds memory writes or reads, potentially leading to arbitrary code execution or denial of service. The description does not detail the exact circumstances, but the nature of the flaw suggests severe compromise of confidentiality, integrity, or availability when triggered.

Affected Systems

Apache Traffic Server versions 8.0.0 through 8.1.9, 9.0.0 through 9.2.14, and 10.0.0 through 10.1.3 are affected. Users should verify their installed versions against these ranges.

Risk and Exploitability

The CVSS score of 8.4 classifies the bug as high severity, while the EPSS score of less than 1% indicates a low likelihood of current exploitation. The vulnerability is not listed in the CISA KEV catalog. Based on the memory‑corruption nature and the affected experimental plugins, the most likely attack vector is remote through a plugin‑enabled request or buffer overflow in plugin code. Once triggered, an attacker could gain code execution, compromising the server.

Generated by OpenCVE AI on August 2, 2026 at 08:02 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Apache Traffic Server to version 9.2.15 or 10.1.4 to obtain the patched plugin code.
  • If an upgrade cannot be performed immediately, disable or remove experimental plugins from the server configuration to prevent the vulnerable code from executing.
  • Apply network or application‑level filtering to restrict access to the plugin handling endpoint and monitor for anomalous traffic patterns that may indicate exploitation attempts.

Generated by OpenCVE AI on August 2, 2026 at 08:02 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 29 Jul 2026 12:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 29 Jul 2026 11:30:00 +0000

Type Values Removed Values Added
First Time appeared Apache
Apache traffic Server
Vendors & Products Apache
Apache traffic Server

Wed, 29 Jul 2026 09:30:00 +0000

Type Values Removed Values Added
Description Several Apache Traffic Server experimental plugins have memory-safety and limit-bypass errors. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.
Title Apache Traffic Server: Memory-safety and limit-bypass errors across experimental plugins
Weaknesses CWE-787
References
Metrics cvssV3_1

{'score': 8.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H'}

cvssV4_0

{'score': 8.4, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:L/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Apache Traffic Server
cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published:

Updated: 2026-07-29T12:11:13.386Z

Reserved: 2026-06-29T16:36:12.204Z

Link: CVE-2026-58188

cve-icon Vulnrichment

Updated: 2026-07-29T12:11:09.821Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-29T10:16:44.093

Modified: 2026-08-03T13:39:15.633

Link: CVE-2026-58188

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-02T08:15:17Z

Weaknesses