CVE-2026-57834: Apache Traffic Server: Malformed chunked message body allows request smuggling
Apache Traffic Server allows request smuggling if chunked messages are malformed.
This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3.
Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Apache Traffic Serverto a version that resolves this vulnerability.Fixed in 9.2.15 - Upgrade
Upgrade
Apache Traffic Serverto a version that resolves this vulnerability.Fixed in 10.1.4
Event History
Frequently Asked Questions
What is the severity of CVE-2026-57834?
The severity of CVE-2026-57834 is critical with a score of 10.
How do I fix CVE-2026-57834?
To fix CVE-2026-57834, upgrade to Apache Traffic Server version 9.2.15 or 10.1.4.
What is CVE-2026-57834 about?
CVE-2026-57834 details a vulnerability in Apache Traffic Server that allows request smuggling due to malformed chunked messages.
Which versions of Apache Traffic Server are affected by CVE-2026-57834?
Apache Traffic Server versions from 8.0.0 to 8.1.9, 9.0.0 to 9.2.14, and 10.0.0 to 10.1.3 are affected by CVE-2026-57834.
What types of impacts can CVE-2026-57834 cause?
CVE-2026-57834 can lead to severe impacts including unauthorized access, data compromise, and potential denial of service.