SEPTEMBER 15, 2026
Live Feed
Back to database
Case File

CVE-2026-58187

LOW · CVSS 3.7 EPSS 0.34%

Source: NVD + CISA KEV + EPSS · Published 2026-07-29 · Last synced 2026-08-28

CyberRota Analysis

AI-Generated

The Apache Traffic Server multiplexer plugin is vulnerable to a buffer overflow in its chunk-decode buffer, which can lead to denial of service when processing upstream input. This issue affects versions 8.0.0 to 8.1.9, 9.0.0 to 9.2.14, and 10.0.0 to 10.1.3. Organizations using affected versions should prioritize upgrading to versions 9.2.15 or 10.1.4 to mitigate potential disruptions.

CVE
CVE-2026-58187
Severity
LOW
CVSS
3.7
EPSS
0.34%
Apache

Original NVD Description

The Apache Traffic Server multiplexer plugin overruns its chunk-decode buffer on upstream input, enabling denial of service. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.

Related CVEs

Other vulnerabilities affecting the same vendor(s)