CVE-2026-22068: Apache Traffic Server: Regex mappings match with malicious domain names
Regular Expression without Anchors vulnerability in Apache Traffic Server.
This issue affects Apache Traffic Server: from 10.0.X through 10.1.3, from 9.0.X through 9.2.14.
Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fixes the issue.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Apache Traffic Serverto a version that resolves this vulnerability.Fixed in 9.2.15 - Upgrade
Upgrade
Apache Traffic Serverto a version that resolves this vulnerability.Fixed in 10.1.4
Event History
Frequently Asked Questions
What is the severity of CVE-2026-22068?
The severity of CVE-2026-22068 is rated high with a score of 8.2.
How do I fix CVE-2026-22068?
To fix CVE-2026-22068, users should upgrade Apache Traffic Server to version 9.2.15 or 10.1.4.
What is CVE-2026-22068 about?
CVE-2026-22068 describes a Regular Expression without Anchors vulnerability in Apache Traffic Server that allows matches with malicious domain names.
Which versions of Apache Traffic Server are affected by CVE-2026-22068?
CVE-2026-22068 affects Apache Traffic Server versions from 10.0.X through 10.1.3 and from 9.0.X through 9.2.14.
What are the potential impacts of CVE-2026-22068?
The potential impacts of CVE-2026-22068 include exposure to malicious domain name matches, which could lead to security risks.