CVE-2026-58188: Apache Traffic Server: Memory-safety and limit-bypass errors across experimental plugins
Several Apache Traffic Server experimental plugins have memory-safety and limit-bypass errors.
This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3.
Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Apache Traffic Serverto a version that resolves this vulnerability.Fixed in 9.2.15 - Upgrade
Upgrade
Apache Traffic Serverto a version that resolves this vulnerability.Fixed in 10.1.4
Event History
Frequently Asked Questions
What is the severity of CVE-2026-58188?
The severity of CVE-2026-58188 is rated high with a score of 8.2.
What are the affected versions of Apache Traffic Server in CVE-2026-58188?
CVE-2026-58188 affects Apache Traffic Server versions from 8.0.0 through 8.1.9, 9.0.0 through 9.2.14, and 10.0.0 through 10.1.3.
How do I fix CVE-2026-58188?
To fix CVE-2026-58188, users should upgrade to Apache Traffic Server version 9.2.15 or 10.1.4.
What type of errors are associated with CVE-2026-58188?
CVE-2026-58188 is associated with memory-safety and limit-bypass errors across experimental plugins in Apache Traffic Server.
Are there any recommended actions for CVE-2026-58188?
Users are recommended to upgrade their Apache Traffic Server installations to the fixed versions to mitigate this vulnerability.