CVE-2026-58159: Apache Traffic Server: Listener and ACL handling allow access-control bypass
Apache Traffic Server can bypass IP access controls on UDS listeners and through ACL matching errors.
This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3.
Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 9.2.15 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.1.4
Event History
Frequently Asked Questions
What is the severity of CVE-2026-58159?
CVE-2026-58159 has a high severity rating of 7.
How do I fix CVE-2026-58159?
To fix CVE-2026-58159, upgrade Apache Traffic Server to version 9.2.15 or 10.1.4.
What issue does CVE-2026-58159 describe?
CVE-2026-58159 describes a vulnerability that allows access-control bypass on UDS listeners and through ACL matching errors.
Which versions of Apache Traffic Server are affected by CVE-2026-58159?
CVE-2026-58159 affects Apache Traffic Server versions from 8.0.0 through 8.1.9, 9.0.0 through 9.2.14, and 10.0.0 through 10.1.3.
Who is impacted by CVE-2026-58159?
Users of Apache Traffic Server within the affected version ranges are impacted by CVE-2026-58159.