CVE-2026-58150: Apache Traffic Server: HTTP/2 requests with Transfer-Encoding are not rejected, allowing request smuggling
Apache Traffic Server does not reject Transfer-Encoding in HTTP/2 requests, allowing downgrade request smuggling.
This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3.
Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Apache Traffic Serverto a version that resolves this vulnerability.Fixed in 9.2.15 - Upgrade
Upgrade
Apache Traffic Serverto a version that resolves this vulnerability.Fixed in 10.1.4
Event History
Frequently Asked Questions
What is the severity of CVE-2026-58150?
CVE-2026-58150 has a critical severity rating of 10.
How do I fix CVE-2026-58150?
To fix CVE-2026-58150, upgrade Apache Traffic Server to version 9.2.15 or 10.1.4.
What does CVE-2026-58150 affect?
CVE-2026-58150 affects Apache Traffic Server versions 8.0.0 through 8.1.9, 9.0.0 through 9.2.14, and 10.0.0 through 10.1.3.
What type of attack can CVE-2026-58150 lead to?
CVE-2026-58150 can lead to request smuggling attacks due to improper handling of Transfer-Encoding in HTTP/2 requests.
Is CVE-2026-58150 a widespread vulnerability?
Yes, CVE-2026-58150 is a serious vulnerability that impacts a range of Apache Traffic Server versions commonly used in production.