CVE-2026-58156: Apache Traffic Server: URL and port parsing errors allow access-control bypass
Apache Traffic Server mis-parses ports in URLs and userinfo, allowing port-based access-control bypass.
This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3.
Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Apache Traffic Serverto a version that resolves this vulnerability.Fixed in 9.2.15 - Upgrade
Upgrade
Apache Traffic Serverto a version that resolves this vulnerability.Fixed in 10.1.4
Event History
Frequently Asked Questions
What is the severity of CVE-2026-58156?
The severity of CVE-2026-58156 is medium with a CVSS score of 4.9.
How do I fix CVE-2026-58156?
To fix CVE-2026-58156, users should upgrade to Apache Traffic Server version 9.2.15 or 10.1.4.
What does CVE-2026-58156 affect?
CVE-2026-58156 affects Apache Traffic Server versions from 8.0.0 through 10.1.3.
What type of vulnerability is CVE-2026-58156?
CVE-2026-58156 is an access-control bypass vulnerability due to URL and port parsing errors.
Can CVE-2026-58156 be exploited remotely?
Yes, CVE-2026-58156 can be exploited remotely due to the nature of the vulnerability.