CVE-2026-58182: Apache Traffic Server: ts_lua plugin has initialization and resource-handling errors
The Apache Traffic Server tslua plugin mishandles initialization, transform context, and per-instance state.
This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3.
Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Apache Traffic Server (ts_lua plugin)to a version that resolves this vulnerability.Fixed in 9.2.15 - Upgrade
Upgrade
Apache Traffic Server (ts_lua plugin)to a version that resolves this vulnerability.Fixed in 10.1.4
Event History
Frequently Asked Questions
What is the severity of CVE-2026-58182?
CVE-2026-58182 has a severity score of 8.6, which is categorized as high.
How do I fix CVE-2026-58182?
To fix CVE-2026-58182, upgrade your Apache Traffic Server to version 9.2.15 or 10.1.4 or later.
What does CVE-2026-58182 affect?
CVE-2026-58182 affects the ts_lua plugin in Apache Traffic Server versions 8.0.0 through 8.1.9, 9.0.0 through 9.2.14, and 10.0.0 through 10.1.3.
What type of vulnerabilities does CVE-2026-58182 exploit?
CVE-2026-58182 exploits initialization and resource-handling errors within the ts_lua plugin.
When was CVE-2026-58182 published?
CVE-2026-58182 was published on July 29, 2026.