| Apache Traffic Server drops the per-stream buffer cap when dechunking HTTP/2 or HTTP/3 responses, letting a slow client exhaust server… CVE-2026-65324 | Severity high |
| Apache Traffic Server updates the HTTP/2 HPACK dynamic table before confirming the header block encoded successfully, so an encode failure… CVE-2026-65100 | Severity medium |
| Apache Traffic Server allows redirect-limit bypass when plugins reset the retry counter, enabling SSRF amplification.
This issue affects… CVE-2026-58189 | Severity high |
| Several Apache Traffic Server experimental plugins have memory-safety and limit-bypass errors.
This issue affects Apache Traffic Server… CVE-2026-58188 | Severity high |
| The Apache Traffic Server multiplexer plugin overruns its chunk-decode buffer on upstream input, enabling denial of service.
This issue… CVE-2026-58187 | Severity high |
| The Apache Traffic Server webp_transform plugin can decode unsafely and serve mislabeled, cacheable responses.
This issue affects Apache… CVE-2026-58186 | Severity high |
| The Apache Traffic Server intercept plugin has a use-after-free.
This issue affects Apache Traffic Server: from 8.0.0 through 8.1.11… CVE-2026-58185 | Severity critical |
| The Apache Traffic Server header_rewrite plugin can crash or corrupt memory during cookie operations and CIDR condition matching.
This… CVE-2026-58184 | Severity high |
| The Apache Traffic Server prefetch plugin can crash when processing attacker-influenced input.
This issue affects Apache Traffic Server… CVE-2026-58183 | Severity high |
| The Apache Traffic Server ts_lua plugin mishandles initialization, transform context, and per-instance state.
This issue affects Apache… CVE-2026-58182 | Severity high |
| The Apache Traffic Server uri_signing and url_sig plugins can exhaust the stack or crash on attacker input.
This issue affects Apache… CVE-2026-58181 | Severity high |
| The Apache Traffic Server txn_box plugin overflows the stack from attacker-controlled input.
This issue affects Apache Traffic Server… CVE-2026-58180 | Severity high |
| The Apache Traffic Server regex_remap plugin overflows the stack and integers from substitution input.
This issue affects Apache Traffic… CVE-2026-58179 | Severity critical |
| The Apache Traffic Server ESI plugin can recurse without bound and fetch attacker-controlled URLs.
This issue affects Apache Traffic… CVE-2026-58178 | Severity high |
| Apache Traffic Server leaks memory when handling HostDB SRV records.
This issue affects Apache Traffic Server: from 8.0.0 through… CVE-2026-58175 | Severity high |
| Apache Traffic Server has use-after-free and time-of-check/time-of-use errors in remap configuration handling.
This issue affects Apache… CVE-2026-58164 | Severity high |
| Apache Traffic Server mishandles on-disk cache fields and object lifetimes, corrupting state or crashing.
This issue affects Apache… CVE-2026-58163 | Severity critical |
| The Apache Traffic Server certifier plugin generates certificates based on attacker-controlled client SNI.
This issue affects Apache… CVE-2026-58162 | Severity critical |
| Apache Traffic Server can crash from null dereferences and dangling references in TLS and SNI handling.
This issue affects Apache… CVE-2026-58161 | Severity high |
| Apache Traffic Server reads out of bounds while parsing DNS answers.
This issue affects Apache Traffic Server: from 8.0.0 through… CVE-2026-58160 | Severity medium |
| Apache Traffic Server can bypass IP access controls on UDS listeners and through ACL matching errors.
This issue affects Apache Traffic… CVE-2026-58159 | Severity high |
| Apache Traffic Server mishandles PROXY protocol input, truncating ports and overflowing the stack.
This issue affects Apache Traffic… CVE-2026-58158 | Severity medium |
| Apache Traffic Server can reuse server sessions and tunnels improperly, exposing data across client connections.
This issue affects… CVE-2026-58157 | Severity high |
| Apache Traffic Server mis-parses ports in URLs and userinfo, allowing port-based access-control bypass.
This issue affects Apache… CVE-2026-58156 | Severity medium |
| Apache Traffic Server truncates over-long header names, allowing header aliasing, request smuggling, and policy bypass.
This issue… CVE-2026-58155 | Severity critical |
| Apache Traffic Server can write out of bounds or overflow integers while parsing MIME and HTTP headers.
This issue affects Apache… CVE-2026-58154 | Severity high |
| Apache Traffic Server mishandles integers while decoding HPACK/XPACK headers, corrupting memory.
This issue affects Apache Traffic… CVE-2026-58152 | Severity medium |
| Apache Traffic Server can be crashed or driven to resource exhaustion by abusive HTTP/2 framing and flow-control.
This issue affects… CVE-2026-58151 | Severity high |
| Apache Traffic Server does not reject Transfer-Encoding in HTTP/2 requests, allowing downgrade request smuggling.
This issue affects… CVE-2026-58150 | Severity critical |
| Apache Traffic Server allows request smuggling if chunked messages are malformed.
This issue affects Apache Traffic Server: from 8.0.0… CVE-2026-57834 | Severity critical |
| Apache Traffic Server copies the client Host header into a fixed-size stack buffer without a bound during redirect handling, so an… CVE-2026-33930 | Severity medium |