CVE-2026-58160: Apache Traffic Server: Out-of-bounds reads while parsing DNS responses
Apache Traffic Server reads out of bounds while parsing DNS answers.
This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3.
Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Apache Traffic Serverto a version that resolves this vulnerability.Fixed in 9.2.15 - Upgrade
Upgrade
Apache Traffic Serverto a version that resolves this vulnerability.Fixed in 10.1.4
Event History
Frequently Asked Questions
What is the severity of CVE-2026-58160?
The severity of CVE-2026-58160 is rated as medium with a score of 6.3.
How do I fix CVE-2026-58160?
To fix CVE-2026-58160, upgrade to Apache Traffic Server version 9.2.15 or 10.1.4.
What are the affected versions for CVE-2026-58160?
CVE-2026-58160 affects Apache Traffic Server versions from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, and from 10.0.0 through 10.1.3.
What vulnerability type is CVE-2026-58160?
CVE-2026-58160 is classified as an out-of-bounds read vulnerability while parsing DNS responses.
What impact can CVE-2026-58160 have on Apache Traffic Server?
CVE-2026-58160 can lead to potential information disclosure due to out-of-bounds reads.