CVE-2026-58177: Apache Traffic Server: Memory-safety and path-traversal errors in the Cripts framework
The Apache Traffic Server Cripts framework has out-of-bounds writes, path traversal, and use-after-free errors.
This issue affects Apache Traffic Server: from 10.0.0 through 10.1.3.
Users are recommended to upgrade to version 10.1.4, which fix the issue.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Apache Traffic Server (Cripts framework)to a version that resolves this vulnerability.Fixed in 10.1.4
Event History
Frequently Asked Questions
What is the severity of CVE-2026-58177?
CVE-2026-58177 has a severity rating of 8.3, indicating a high risk level.
How do I fix CVE-2026-58177?
To fix CVE-2026-58177, users should upgrade Apache Traffic Server to version 10.1.4 or higher.
What vulnerabilities are present in CVE-2026-58177?
CVE-2026-58177 includes memory-safety issues, out-of-bounds writes, path traversal, and use-after-free errors.
Which versions of Apache Traffic Server are affected by CVE-2026-58177?
CVE-2026-58177 affects Apache Traffic Server versions from 10.0.0 through 10.1.3.
What should I do if I am using an affected version of Apache Traffic Server?
If using an affected version of Apache Traffic Server, it is critical to upgrade to version 10.1.4 to mitigate the vulnerabilities.