SEPTEMBER 20, 2026
Live Feed
Back to database
Case File

CVE-2026-58180

HIGH · CVSS 7.5 EPSS 0.40%

Source: NVD + CISA KEV + EPSS · Published 2026-07-29 · Last synced 2026-08-28

CyberRota Analysis

AI-Generated

The Apache Traffic Server's txn_box plugin is vulnerable to a stack overflow due to attacker-controlled input, impacting versions 8.0.0 to 8.1.9, 9.0.0 to 9.2.14, and 10.0.0 to 10.1.3. This vulnerability can lead to potential remote code execution, making it critical for organizations using affected versions to prioritize upgrading to versions 9.2.15 or 10.1.4 to mitigate the risk. Security teams and system administrators should act promptly to protect their infrastructure from exploitation.

CVE
CVE-2026-58180
Severity
HIGH
CVSS
7.5
EPSS
0.40%
Apache

Original NVD Description

The Apache Traffic Server txn_box plugin overflows the stack from attacker-controlled input. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.

Related CVEs

Other vulnerabilities affecting the same vendor(s)