Apache / Apache Traffic Server
95 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-65100 | Apache Traffic Server: HPACK encoder desynchronizes from the decoder after a failed header encode | MEDIUM | 6.3 | Jul 29, 2026 |
| CVE-2026-58189 | Apache Traffic Server: Plugins resetting the redirect counter enable SSRF amplification | HIGH | 8.2 | Jul 29, 2026 |
| CVE-2026-58188 | Apache Traffic Server: Memory-safety and limit-bypass errors across experimental plugins | HIGH | 8.4 | Jul 29, 2026 |
| CVE-2026-58187 | Apache Traffic Server: Multiplexer plugin chunk decoder enables a denial of service | MEDIUM | 6.3 | Jul 29, 2026 |
| CVE-2026-58186 | Apache Traffic Server: webp_transform plugin decodes unsafely and mislabels degraded responses | HIGH | 8.2 | Jul 29, 2026 |
| CVE-2026-58185 | Apache Traffic Server: Use-after-free in the intercept plugin | HIGH | 8.2 | Jul 29, 2026 |
| CVE-2026-58184 | Apache Traffic Server: header_rewrite plugin cookie handling can corrupt memory | HIGH | 8.3 | Jul 29, 2026 |
| CVE-2026-58183 | Apache Traffic Server: prefetch plugin can crash on attacker-influenced input | HIGH | 8.2 | Jul 29, 2026 |
| CVE-2026-58182 | Apache Traffic Server: ts_lua plugin has initialization and resource-handling errors | HIGH | 8.2 | Jul 29, 2026 |
| CVE-2026-58181 | Apache Traffic Server: uri_signing and url_sig plugins can exhaust the stack or crash | HIGH | 8.2 | Jul 29, 2026 |
| CVE-2026-58180 | Apache Traffic Server: txn_box plugin overflows the stack from attacker input | HIGH | 8.2 | Jul 29, 2026 |
| CVE-2026-58179 | Apache Traffic Server: regex_remap plugin overflows the stack from attacker input | CRITICAL | 9.2 | Jul 29, 2026 |
| CVE-2026-58178 | Apache Traffic Server: ESI plugin allows uncontrolled recursion and server-side request forgery | HIGH | 8.2 | Jul 29, 2026 |
| CVE-2026-58177 | Apache Traffic Server: Memory-safety and path-traversal errors in the Cripts framework | HIGH | 8.3 | Jul 29, 2026 |
| CVE-2026-58175 | Apache Traffic Server: HostDB SRV handling leaks memory | HIGH | 8.2 | Jul 29, 2026 |
| CVE-2026-58164 | Apache Traffic Server: Remap configuration lifetime and TOCTOU errors cause use-after-free | HIGH | 8.3 | Jul 29, 2026 |
| CVE-2026-58163 | Apache Traffic Server: Cache deserialization and lifetime errors can corrupt state or crash the server | HIGH | 8.3 | Jul 29, 2026 |
| CVE-2026-58162 | Apache Traffic Server: Certifier plugin trusts client SNI when generating certificates | HIGH | 8.4 | Jul 29, 2026 |
| CVE-2026-58161 | Apache Traffic Server: Memory-safety errors in TLS and SNI handling can crash the server | CRITICAL | 9.2 | Jul 29, 2026 |
| CVE-2026-58160 | Apache Traffic Server: Out-of-bounds reads while parsing DNS responses | MEDIUM | 6.3 | Jul 29, 2026 |
| CVE-2026-58159 | Apache Traffic Server: Listener and ACL handling allow access-control bypass | HIGH | 7.0 | Jul 29, 2026 |
| CVE-2026-58158 | Apache Traffic Server: PROXY protocol parsing has port truncation and a stack overflow | HIGH | 8.2 | Jul 29, 2026 |
| CVE-2026-58157 | Apache Traffic Server: Improper server-session reuse can expose data across client connections | MEDIUM | 6.9 | Jul 29, 2026 |
| CVE-2026-58156 | Apache Traffic Server: URL and port parsing errors allow access-control bypass | MEDIUM | 6.3 | Jul 29, 2026 |
| CVE-2026-58155 | Apache Traffic Server: Header-name length truncation enables header aliasing and request smuggling | CRITICAL | 9.2 | Jul 29, 2026 |
Showing 1 to 25 of 95 CVEs