CVE-2026-58184: Apache Traffic Server: header_rewrite plugin cookie handling can corrupt memory
The Apache Traffic Server headerrewrite plugin can crash or corrupt memory during cookie operations and CIDR condition matching.
This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3.
Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Apache Traffic Serverto a version that resolves this vulnerability.Fixed in 9.2.15 - Upgrade
Upgrade
Apache Traffic Serverto a version that resolves this vulnerability.Fixed in 10.1.4
Event History
Frequently Asked Questions
What is the severity of CVE-2026-58184?
CVE-2026-58184 has a severity rating of high, with a score of 8.2.
How do I fix CVE-2026-58184?
To mitigate CVE-2026-58184, upgrade Apache Traffic Server to version 9.2 or later.
What systems are affected by CVE-2026-58184?
CVE-2026-58184 affects Apache Traffic Server versions from 8.0.0 through 8.1.9, 9.0.0 through 9.2.14, and 10.0.0 through 10.1.3.
What type of vulnerability is CVE-2026-58184?
CVE-2026-58184 is a vulnerability in the header_rewrite plugin of Apache Traffic Server that can lead to memory corruption.
What should I do if I cannot upgrade to fix CVE-2026-58184?
If upgrading is not possible, consider disabling the header_rewrite plugin to prevent memory corruption issues related to CVE-2026-58184.