CVE-2026-58181: Apache Traffic Server: uri_signing and url_sig plugins can exhaust the stack or crash
The Apache Traffic Server urisigning and urlsig plugins can exhaust the stack or crash on attacker input.
This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3.
Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Apache Traffic Serverto a version that resolves this vulnerability.Fixed in 9.2.15 - Upgrade
Upgrade
Apache Traffic Serverto a version that resolves this vulnerability.Fixed in 10.1.4
Event History
Frequently Asked Questions
What is the severity of CVE-2026-58181?
CVE-2026-58181 has a high severity rating of 7.5.
How do I fix CVE-2026-58181?
To fix CVE-2026-58181, upgrade your Apache Traffic Server to version 9.2.15 or 10.1.4.
Which versions are affected by CVE-2026-58181?
CVE-2026-58181 affects Apache Traffic Server versions from 8.0.0 through 8.1.9, 9.0.0 through 9.2.14, and 10.0.0 through 10.1.3.
What are the potential impacts of CVE-2026-58181?
CVE-2026-58181 can lead to stack exhaustion or crashing of the Apache Traffic Server.
Is user interaction required to exploit CVE-2026-58181?
No, CVE-2026-58181 does not require user interaction to be exploited.