CVE-2026-58153: Apache Traffic Server: HTTP/2 to HTTP/1 conversion forwards origin trailers to clients unsafely
Apache Traffic Server forwards HTTP/2 origin trailers to HTTP/1 clients without proper chunked framing when converting HTTP/2 to HTTP/1.
This issue affects Apache Traffic Server: from 10.0.0 through 10.1.3.
Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Apache Traffic Serverto a version that resolves this vulnerability.Fixed in 9.2.15 - Upgrade
Upgrade
Apache Traffic Serverto a version that resolves this vulnerability.Fixed in 10.1.4
Event History
Frequently Asked Questions
What is the severity of CVE-2026-58153?
CVE-2026-58153 has a high severity score of 8.3.
How do I fix CVE-2026-58153?
To resolve CVE-2026-58153, upgrade to Apache Traffic Server version 9.2.15 or 10.1.4.
What impact does CVE-2026-58153 have on Apache Traffic Server?
CVE-2026-58153 allows unsafe forwarding of HTTP/2 origin trailers to HTTP/1 clients.
Which versions of Apache Traffic Server are affected by CVE-2026-58153?
CVE-2026-58153 affects Apache Traffic Server versions from 10.0.0 through 10.1.3.
What is the risk level associated with CVE-2026-58153?
CVE-2026-58153 has a risk level of 57.