CVE-2026-58189: Apache Traffic Server: Plugins resetting the redirect counter enable SSRF amplification
Apache Traffic Server allows redirect-limit bypass when plugins reset the retry counter, enabling SSRF amplification.
This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3.
Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 9.2.15 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.1.4
Event History
Frequently Asked Questions
What is the severity of CVE-2026-58189?
CVE-2026-58189 has a severity score of 7.5, which is considered high.
How do I fix CVE-2026-58189?
To fix CVE-2026-58189, users should upgrade to Apache Traffic Server version 9.2.15 or 10.1.4 or later.
What impact does CVE-2026-58189 have on my system?
CVE-2026-58189 enables SSRF amplification, which can lead to unauthorized access to internal resources.
Which versions of Apache Traffic Server are affected by CVE-2026-58189?
CVE-2026-58189 affects Apache Traffic Server versions from 8.0.0 through 8.1.9 and 9.0.0 through 9.2.14.
What kind of attack is associated with CVE-2026-58189?
CVE-2026-58189 is associated with Server-Side Request Forgery (SSRF) amplification.