SEPTEMBER 20, 2026
Live Feed
Back to database
Case File

CVE-2026-58181

HIGH · CVSS 7.5 EPSS 0.39%

Source: NVD + CISA KEV + EPSS · Published 2026-07-29 · Last synced 2026-08-28

CyberRota Analysis

AI-Generated

The Apache Traffic Server is vulnerable to a stack exhaustion or crash due to improper handling of attacker input in the uri_signing and url_sig plugins. This vulnerability can lead to service disruption, making it critical for users running affected versions (8.0.0 to 8.1.9, 9.0.0 to 9.2.14, and 10.0.0 to 10.1.3) to prioritize upgrading to versions 9.2.15 or 10.1.4 to mitigate the risk. Organizations relying on Apache Traffic Server for web traffic management should address this issue promptly to maintain service stability and security.

CVE
CVE-2026-58181
Severity
HIGH
CVSS
7.5
EPSS
0.39%
Apache

Original NVD Description

The Apache Traffic Server uri_signing and url_sig plugins can exhaust the stack or crash on attacker input. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.

Related CVEs

Other vulnerabilities affecting the same vendor(s)