SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-58150

CRITICAL · CVSS 10 EPSS 0.37%

Source: NVD + CISA KEV + EPSS · Published 2026-07-29 · Last synced 2026-08-28

CyberRota Analysis

AI-Generated

Apache Traffic Server versions 8.0.0 to 8.1.9, 9.0.0 to 9.2.14, and 10.0.0 to 10.1.3 are vulnerable to a critical downgrade request smuggling attack due to improper handling of Transfer-Encoding in HTTP/2 requests. This vulnerability could allow attackers to manipulate request processing, leading to potential data breaches or service disruptions. Organizations using affected versions should prioritize upgrading to versions 9.2.15 or 10.1.4 to mitigate this risk.

CVE
CVE-2026-58150
Severity
CRITICAL
CVSS
10
EPSS
0.37%
Apache

Original NVD Description

Apache Traffic Server does not reject Transfer-Encoding in HTTP/2 requests, allowing downgrade request smuggling. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.

Related CVEs

Other vulnerabilities affecting the same vendor(s)