SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-58155

CRITICAL · CVSS 9.3 EPSS 0.40%

Source: NVD + CISA KEV + EPSS · Published 2026-07-29 · Last synced 2026-08-28

CyberRota Analysis

AI-Generated

Apache Traffic Server versions 8.0.0 to 8.1.9, 9.0.0 to 9.2.14, and 10.0.0 to 10.1.3 are vulnerable to header aliasing, request smuggling, and policy bypass due to improper handling of over-long header names. This critical vulnerability, with a CVSS score of 9.3, can lead to significant security risks, including unauthorized access and data manipulation. Organizations using affected versions should prioritize upgrading to versions 9.2.15 or 10.1.4 to mitigate these risks.

CVE
CVE-2026-58155
Severity
CRITICAL
CVSS
9.3
EPSS
0.40%
Apache

Original NVD Description

Apache Traffic Server truncates over-long header names, allowing header aliasing, request smuggling, and policy bypass. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.

Related CVEs

Other vulnerabilities affecting the same vendor(s)