CVE-2026-58180: Apache Traffic Server: txn_box plugin overflows the stack from attacker input
The Apache Traffic Server txnbox plugin overflows the stack from attacker-controlled input.
This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3.
Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Apache Traffic Serverto a version that resolves this vulnerability.Fixed in 9.2.15 - Upgrade
Upgrade
Apache Traffic Serverto a version that resolves this vulnerability.Fixed in 10.1.4
Event History
Frequently Asked Questions
What is the severity of CVE-2026-58180?
The severity of CVE-2026-58180 is rated high with a score of 8.2.
How do I fix CVE-2026-58180?
To fix CVE-2026-58180, it is recommended to upgrade to Apache Traffic Server version 9.2.15 or 10.1.4.
What does CVE-2026-58180 affect?
CVE-2026-58180 affects Apache Traffic Server versions from 8.0.0 through 8.1.9, 9.0.0 through 9.2.14, and 10.0.0 through 10.1.3.
What type of vulnerability is CVE-2026-58180?
CVE-2026-58180 is a stack overflow vulnerability caused by attacker-controlled input in the txn_box plugin.
When was CVE-2026-58180 published?
CVE-2026-58180 was published on July 29, 2026.