CVE-2025-58136: Apache Traffic Server: A simple legitimate POST request causes a crash
Published Apr 2, 2026
·Updated
A bug in POST request handling causes a crash under a certain condition.
This issue affects Apache Traffic Server: from 10.0.0 through 10.1.1, from 9.0.0 through 9.2.12.
Users are recommended to upgrade to version 10.1.2 or 9.2.13, which fix the issue.
A workaround for older versions is to set proxy.config.http.requestbufferenabled to 0 (the default value is 0).
Affected Software
2 affected components
Apache Traffic Server>=9.0.0<9.2.13
Apache Traffic Server>=10.0.0<10.1.2
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Apache Traffic Serverto a version that resolves this vulnerability.Fixed in 10.1.2 - Upgrade
Upgrade
Apache Traffic Serverto a version that resolves this vulnerability.Fixed in 9.2.13 - Configuration
For affected older versions where a workaround is needed, set proxy.config.http.request_buffer_enabled to 0.
Apache Traffic Server proxy.config.http.request_buffer_enabled = 0
Event History
Apr 2, 2026
CVE Published
via MITRE·03:54 PM
Data Sourced
via MITRE·03:54 PM
DescriptionWeakness
Data Sourced
via NVD·05:16 PM
DescriptionSeverityWeaknessAffected Software