Known vulnerabilities in trafficserver
Vendor:
Fedoraproject
Software:
trafficserver
Software CPE:
cpe:2.3:o:fedoraproject:trafficserver:*:*:*:*:*:fedora:*:*
Website:
https://getfedora.org/
Total vulnerabilities:
61
Public exploits:
1
Known exploited (KEV):
1
Highest CVSSv4 Score:
9.3
Breakdown by Severity Chart
10.2.0-1.fc43
10.2.0-1.fc44
10.1.4-1.fc43
10.1.4-1.fc44
9.2.15-1.el9
9.2.15-1.el8
10.1.3-1.fc43
10.1.3-1.fc44
9.2.14-1.el9
9.2.14-1.el8
10.1.2-1.fc43
10.1.2-1.fc44
10.1.2-1.fc42
9.2.13-1.el9
9.2.13-1.el8
5.3.0-1.fc21
5.3.0-1.fc22
5.3.0-1.el6
5.3.0-1.el7
9.2.10-1.fc40
9.2.10-1.el9
10.0.5-1.fc42
9.2.10-1.fc41
9.2.10-1.el8
9.2.9-1.fc40
9.2.9-1.el9
9.2.9-1.el8
9.2.9-1.fc41
9.1.4-1.fc36
9.1.4-1.el7
9.1.4-1.fc37
9.1.4-1.el8
9.1.4-1.el9
9.1.3-1.el9
9.1.3-1.el8
9.1.3-1.el7
9.1.3-1.fc35
9.1.3-1.fc36
9.2.6-2.fc39
9.2.6-2.fc40
9.2.6-2.fc41
9.2.6-2.el9
9.2.6-2.el8
9.2.5-1.el8
9.2.5-1.fc40
9.2.5-1.el9
9.2.5-1.fc39
9.2.4-1.fc39
9.2.4-1.fc38
9.2.4-1.fc40
9.2.4-1.el8
9.2.4-1.el9
9.2.4-1.el7
9.2.3-1.el7
9.2.3-1.el8
9.2.3-1.el9
9.2.3-1.fc37
9.2.3-1.fc39
9.2.3-1.fc38
9.2.1-1.el7
9.2.1-1.fc38
9.2.1-1.fc37
9.2.1-1.el8
9.2.1-1.el9
Vulnerabilities (61)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU145206 - Resource exhaustion CVE-2026-59173 |
CWE-400 | Medium | 9.2.14-1.el8, 9.2.14-1.el9, 10.1.3-1.fc43, 10.1.3-1.fc44 | 25.08.2026 |
SB20260824137 SB2026082580 SB2026082581 and 5 more |
||
| #VU144899 - Resource exhaustion CVE-2026-65324 |
CWE-400 | Medium | 9.2.15-1.el8, 9.2.15-1.el9, 10.1.4-1.fc43, 10.1.4-1.fc44 | 24.08.2026 |
SB20260824179 SB20260824184 SB20260824185 and 5 more |
||
| #VU144900 - Stack-based buffer overflow CVE-2026-33930 |
CWE-121 | Medium | 9.2.15-1.el8, 9.2.15-1.el9, 10.1.4-1.fc43, 10.1.4-1.fc44 | 24.08.2026 |
SB20260824179 SB20260824184 SB20260824185 and 5 more |
||
| #VU144782 - Stack-based buffer overflow CVE-2026-58180 |
CWE-121 | Medium | 9.2.15-1.el8, 9.2.15-1.el9, 10.1.4-1.fc43, 10.1.4-1.fc44 | 24.08.2026 |
SB20260824137 SB20260824184 SB20260824185 and 5 more |
||
| #VU144786 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') CVE-2026-24033 |
CWE-444 | High | 9.2.15-1.el8, 9.2.15-1.el9, 10.1.4-1.fc43, 10.1.4-1.fc44 | 24.08.2026 |
SB20260824137 SB20260824184 SB20260824185 and 5 more |
||
| #VU144787 - Out-of-bounds read CVE-2026-58160 |
CWE-125 | Medium | 9.2.15-1.el8, 9.2.15-1.el9, 10.1.4-1.fc43, 10.1.4-1.fc44, 10.2.0-1.fc43, 10.2.0-1.fc44 | 24.08.2026 |
SB20260824137 SB20260824184 SB20260824185 and 7 more |
||
| #VU144788 - Integer overflow CVE-2026-58152 |
CWE-190 | Medium | 9.2.15-1.el8, 9.2.15-1.el9, 10.1.4-1.fc43, 10.1.4-1.fc44 | 24.08.2026 |
SB20260824137 SB20260824184 SB20260824185 and 5 more |
||
| #VU144789 - Stack-based buffer overflow CVE-2026-58158 |
CWE-121 | Medium | 9.2.15-1.el8, 9.2.15-1.el9, 10.1.4-1.fc43, 10.1.4-1.fc44, 10.2.0-1.fc43, 10.2.0-1.fc44 | 24.08.2026 |
SB20260824137 SB20260824184 SB20260824185 and 7 more |
||
| #VU144792 - Improper input validation CVE-2026-58156 |
CWE-20 | Medium | 9.2.15-1.el8, 9.2.15-1.el9, 10.1.4-1.fc43, 10.1.4-1.fc44 | 24.08.2026 |
SB20260824137 SB20260824184 SB20260824185 and 5 more |
||
| #VU144766 - Out-of-bounds write CVE-2026-58177 |
CWE-787 | High | 9.2.15-1.el8, 9.2.15-1.el9, 10.1.4-1.fc43, 10.1.4-1.fc44 | 24.08.2026 |
SB20260824137 SB20260824184 SB20260824185 and 2 more |
||
| #VU144769 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') CVE-2026-57834 |
CWE-444 | High | 9.2.15-1.el8, 9.2.15-1.el9, 10.1.4-1.fc43, 10.1.4-1.fc44 | 24.08.2026 |
SB20260824137 SB20260824184 SB20260824185 and 5 more |
||
| #VU144770 - Authentication Bypass by Spoofing CVE-2026-58162 |
CWE-290 | High | 9.2.15-1.el8, 9.2.15-1.el9, 10.1.4-1.fc43, 10.1.4-1.fc44 | 24.08.2026 |
SB20260824137 SB20260824184 SB20260824185 and 5 more |
||
| #VU144771 - Incorrect Comparison CVE-2026-41920 |
CWE-697 | High | 9.2.15-1.el8, 9.2.15-1.el9, 10.1.4-1.fc43, 10.1.4-1.fc44 | 24.08.2026 |
SB20260824137 SB20260824184 SB20260824185 and 5 more |
||
| #VU144773 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') CVE-2026-58153 |
CWE-444 | High | 9.2.15-1.el8, 9.2.15-1.el9, 10.1.4-1.fc43, 10.1.4-1.fc44 | 24.08.2026 |
SB20260824137 SB20260824184 SB20260824185 and 5 more |
||
| #VU144774 - Improper Access Control CVE-2026-58159 |
CWE-284 | Medium | 9.2.15-1.el8, 9.2.15-1.el9, 10.1.4-1.fc43, 10.1.4-1.fc44 | 24.08.2026 |
SB20260824137 SB20260824184 SB20260824185 and 5 more |
||
| #VU144777 - Stack-based buffer overflow CVE-2026-58179 |
CWE-121 | High | 9.2.15-1.el8, 9.2.15-1.el9, 10.1.4-1.fc43, 10.1.4-1.fc44, 10.2.0-1.fc43, 10.2.0-1.fc44 | 24.08.2026 |
SB20260824137 SB20260824184 SB20260824185 and 7 more |
||
| #VU144778 - Deserialization of Untrusted Data CVE-2026-58163 |
CWE-502 | High | 9.2.15-1.el8, 9.2.15-1.el9, 10.1.4-1.fc43, 10.1.4-1.fc44 | 24.08.2026 |
SB20260824137 SB20260824184 SB20260824185 and 5 more |
||
| #VU144779 - Use After Free CVE-2026-58164 |
CWE-416 | Medium | 9.2.15-1.el8, 9.2.15-1.el9, 10.1.4-1.fc43, 10.1.4-1.fc44, 10.2.0-1.fc43, 10.2.0-1.fc44 | 24.08.2026 |
SB20260824137 SB20260824184 SB20260824185 and 7 more |
||
| #VU144780 - Missing release of memory after effective lifetime CVE-2026-58175 |
CWE-401 | Medium | 9.2.15-1.el8, 9.2.15-1.el9, 10.1.4-1.fc43, 10.1.4-1.fc44 | 24.08.2026 |
SB20260824137 SB20260824184 SB20260824185 and 5 more |
||
| #VU144781 - Server-Side Request Forgery (SSRF) CVE-2026-58178 |
CWE-918 | Medium | 9.2.15-1.el8, 9.2.15-1.el9, 10.1.4-1.fc43, 10.1.4-1.fc44 | 24.08.2026 |
SB20260824137 SB20260824184 SB20260824185 and 5 more |
Showing elements 1 - 20 out of 61