CVE-2026-58183: Apache Traffic Server: prefetch plugin can crash on attacker-influenced input
The Apache Traffic Server prefetch plugin can crash when processing attacker-influenced input.
This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3.
Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 9.2.15 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.1.4
Event History
Frequently Asked Questions
What is the severity of CVE-2026-58183?
The severity of CVE-2026-58183 is rated as medium with a score of 5.9.
How do I fix CVE-2026-58183?
To fix CVE-2026-58183, upgrade Apache Traffic Server to version 9.2.15 or 10.1.4.
What versions of Apache Traffic Server are affected by CVE-2026-58183?
CVE-2026-58183 affects Apache Traffic Server versions from 8.0.0 through 8.1.9, 9.0.0 through 9.2.14, and 10.0.0 through 10.1.3.
What is the cause of CVE-2026-58183?
CVE-2026-58183 is caused by the prefetch plugin crashing when it processes attacker-influenced input.
What type of vulnerability is CVE-2026-58183 classified as?
CVE-2026-58183 is classified as an Input Validation vulnerability.