SEPTEMBER 20, 2026
Live Feed
Back to database
Case File

CVE-2026-58188

HIGH · CVSS 8.2 EPSS 0.43%

Source: NVD + CISA KEV + EPSS · Published 2026-07-29 · Last synced 2026-08-28

CyberRota Analysis

AI-Generated

Several experimental plugins in Apache Traffic Server versions 8.0.0 to 8.1.9, 9.0.0 to 9.2.14, and 10.0.0 to 10.1.3 contain memory-safety and limit-bypass vulnerabilities that could be exploited to compromise system integrity. Organizations utilizing these affected versions should prioritize upgrading to versions 9.2.15 or 10.1.4 to mitigate potential security risks. This is particularly critical for environments relying on Apache Traffic Server for handling sensitive data or high-traffic applications.

CVE
CVE-2026-58188
Severity
HIGH
CVSS
8.2
EPSS
0.43%
Apache

Original NVD Description

Several Apache Traffic Server experimental plugins have memory-safety and limit-bypass errors. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.

Related CVEs

Other vulnerabilities affecting the same vendor(s)