CVE-2026-58162: Apache Traffic Server: Certifier plugin trusts client SNI when generating certificates
The Apache Traffic Server certifier plugin generates certificates based on attacker-controlled client SNI.
This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3.
Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Apache Traffic Serverto a version that resolves this vulnerability.Fixed in 9.2.15 - Upgrade
Upgrade
Apache Traffic Serverto a version that resolves this vulnerability.Fixed in 10.1.4
Event History
Frequently Asked Questions
What is the severity of CVE-2026-58162?
The severity of CVE-2026-58162 is high, with a score of 8.4.
How do I fix CVE-2026-58162?
To fix CVE-2026-58162, upgrade Apache Traffic Server to version 9.2.15 or 10.1.4.
What systems are affected by CVE-2026-58162?
CVE-2026-58162 affects Apache Traffic Server versions from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, and from 10.0.0 through 10.1.3.
What is the impact of CVE-2026-58162?
The impact of CVE-2026-58162 is that it allows attackers to control the SNI used for generating certificates, possibly leading to unauthorized access.
Who should be concerned about CVE-2026-58162?
Organizations using the affected versions of Apache Traffic Server should be concerned about CVE-2026-58162 due to potential security risks.