CVE-2026-58157: Apache Traffic Server: Improper server-session reuse can expose data across client connections
Apache Traffic Server can reuse server sessions and tunnels improperly, exposing data across client connections.
This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3.
Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Apache Traffic Serverto a version that resolves this vulnerability.Fixed in 9.2.15 - Upgrade
Upgrade
Apache Traffic Serverto a version that resolves this vulnerability.Fixed in 10.1.4
Event History
Frequently Asked Questions
What is the severity of CVE-2026-58157?
CVE-2026-58157 has a medium severity rating of 6.9.
How do I fix CVE-2026-58157?
To fix CVE-2026-58157, upgrade to Apache Traffic Server version 9.2.15 or 10.1.4.
What are the potential impacts of CVE-2026-58157?
CVE-2026-58157 can lead to improper server-session reuse, potentially exposing sensitive data across client connections.
Which versions of Apache Traffic Server are affected by CVE-2026-58157?
CVE-2026-58157 affects Apache Traffic Server versions from 8.0.0 to 8.1.9, 9.0.0 to 9.2.14, and 10.0.0 to 10.1.3.
What is the nature of the vulnerability described in CVE-2026-58157?
CVE-2026-58157 is characterized as an infoleak due to improper reuse of server sessions.