CVE-2026-58152: Apache Traffic Server: Integer-handling errors in HPACK/XPACK decoding corrupt memory
Apache Traffic Server mishandles integers while decoding HPACK/XPACK headers, corrupting memory.
This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3.
Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Apache Traffic Serverto a version that resolves this vulnerability.Fixed in 9.2.15 - Upgrade
Upgrade
Apache Traffic Serverto a version that resolves this vulnerability.Fixed in 10.1.4
Event History
Frequently Asked Questions
What is the severity of CVE-2026-58152?
The severity of CVE-2026-58152 is classified as medium with a CVSS score of 5.9.
What systems are affected by CVE-2026-58152?
CVE-2026-58152 affects Apache Traffic Server versions from 8.0.0 to 8.1.9, 9.0.0 to 9.2.14, and 10.0.0 to 10.1.3.
How do I fix CVE-2026-58152?
To fix CVE-2026-58152, users should upgrade to Apache Traffic Server version 9.2.15 or 10.1.4.
What kind of vulnerability is CVE-2026-58152?
CVE-2026-58152 is an integer overflow vulnerability that leads to memory corruption in Apache Traffic Server.
What could be the impact of CVE-2026-58152?
The impact of CVE-2026-58152 includes potential memory corruption, which could lead to application crashes or unexpected behavior.