CVE-2026-58155: Apache Traffic Server: Header-name length truncation enables header aliasing and request smuggling
Apache Traffic Server truncates over-long header names, allowing header aliasing, request smuggling, and policy bypass.
This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3.
Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Apache Traffic Serverto a version that resolves this vulnerability.Fixed in 9.2.15 - Upgrade
Upgrade
Apache Traffic Serverto a version that resolves this vulnerability.Fixed in 10.1.4
Event History
Frequently Asked Questions
What is the severity of CVE-2026-58155?
CVE-2026-58155 has a critical severity rating of 9.3.
How do I fix CVE-2026-58155?
To fix CVE-2026-58155, upgrade to Apache Traffic Server version 9.2.15 or later.
What vulnerabilities does CVE-2026-58155 introduce?
CVE-2026-58155 introduces risks of header aliasing, request smuggling, and policy bypass.
Which versions of Apache Traffic Server are affected by CVE-2026-58155?
CVE-2026-58155 affects Apache Traffic Server versions from 8.0.0 to 8.1.9, 9.0.0 to 9.2.14, and 10.0.0 to 10.1.3.
What mitigation strategies exist for CVE-2026-58155?
The primary mitigation for CVE-2026-58155 is to upgrade to the fixed version of Apache Traffic Server.