CVE-2026-58175: Apache Traffic Server: HostDB SRV handling leaks memory
Apache Traffic Server leaks memory when handling HostDB SRV records.
This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3.
Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 9.2.15 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.1.4
Event History
Frequently Asked Questions
What is the severity of CVE-2026-58175?
The severity of CVE-2026-58175 is rated as high with a score of 8.2.
How do I fix CVE-2026-58175?
To fix CVE-2026-58175, users should upgrade to Apache Traffic Server version 9.2.15 or 10.1.4.
What causes CVE-2026-58175?
CVE-2026-58175 is caused by memory leaks in Apache Traffic Server when handling HostDB SRV records.
Which versions of Apache Traffic Server are affected by CVE-2026-58175?
CVE-2026-58175 affects Apache Traffic Server versions from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, and from 10.0.0 through 10.1.3.
Is there a known impact of CVE-2026-58175?
The known impact of CVE-2026-58175 is high, specifically related to the availability of the service due to memory leaks.