Known vulnerabilities in trafficserver

Software: trafficserver
Software CPE: cpe:2.3:o:fedoraproject:trafficserver:*:*:*:*:*:fedora:*:*
Total vulnerabilities: 61
Public exploits: 1
Known exploited (KEV): 1
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting trafficserver trafficserver is affected by 61 known vulnerabilities: 18 high, 41 medium, 2 low Critical High Medium Low

Vulnerabilities (61)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU145206 - Resource exhaustion
CVE-2026-59173
CWE-400 Medium
No
No
9.2.14-1.el8, 9.2.14-1.el9, 10.1.3-1.fc43, 10.1.3-1.fc44 25.08.2026 SB20260824137
SB2026082580
SB2026082581
and 5 more
#VU144899 - Resource exhaustion
CVE-2026-65324
CWE-400 Medium
No
No
9.2.15-1.el8, 9.2.15-1.el9, 10.1.4-1.fc43, 10.1.4-1.fc44 24.08.2026 SB20260824179
SB20260824184
SB20260824185
and 5 more
#VU144900 - Stack-based buffer overflow
CVE-2026-33930
CWE-121 Medium
No
No
9.2.15-1.el8, 9.2.15-1.el9, 10.1.4-1.fc43, 10.1.4-1.fc44 24.08.2026 SB20260824179
SB20260824184
SB20260824185
and 5 more
#VU144782 - Stack-based buffer overflow
CVE-2026-58180
CWE-121 Medium
No
No
9.2.15-1.el8, 9.2.15-1.el9, 10.1.4-1.fc43, 10.1.4-1.fc44 24.08.2026 SB20260824137
SB20260824184
SB20260824185
and 5 more
#VU144786 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling')
CVE-2026-24033
CWE-444 High
No
No
9.2.15-1.el8, 9.2.15-1.el9, 10.1.4-1.fc43, 10.1.4-1.fc44 24.08.2026 SB20260824137
SB20260824184
SB20260824185
and 5 more
#VU144787 - Out-of-bounds read
CVE-2026-58160
CWE-125 Medium
No
No
9.2.15-1.el8, 9.2.15-1.el9, 10.1.4-1.fc43, 10.1.4-1.fc44, 10.2.0-1.fc43, 10.2.0-1.fc44 24.08.2026 SB20260824137
SB20260824184
SB20260824185
and 7 more
#VU144788 - Integer overflow
CVE-2026-58152
CWE-190 Medium
No
No
9.2.15-1.el8, 9.2.15-1.el9, 10.1.4-1.fc43, 10.1.4-1.fc44 24.08.2026 SB20260824137
SB20260824184
SB20260824185
and 5 more
#VU144789 - Stack-based buffer overflow
CVE-2026-58158
CWE-121 Medium
No
No
9.2.15-1.el8, 9.2.15-1.el9, 10.1.4-1.fc43, 10.1.4-1.fc44, 10.2.0-1.fc43, 10.2.0-1.fc44 24.08.2026 SB20260824137
SB20260824184
SB20260824185
and 7 more
#VU144792 - Improper input validation
CVE-2026-58156
CWE-20 Medium
No
No
9.2.15-1.el8, 9.2.15-1.el9, 10.1.4-1.fc43, 10.1.4-1.fc44 24.08.2026 SB20260824137
SB20260824184
SB20260824185
and 5 more
#VU144766 - Out-of-bounds write
CVE-2026-58177
CWE-787 High
No
No
9.2.15-1.el8, 9.2.15-1.el9, 10.1.4-1.fc43, 10.1.4-1.fc44 24.08.2026 SB20260824137
SB20260824184
SB20260824185
and 2 more
#VU144769 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling')
CVE-2026-57834
CWE-444 High
No
No
9.2.15-1.el8, 9.2.15-1.el9, 10.1.4-1.fc43, 10.1.4-1.fc44 24.08.2026 SB20260824137
SB20260824184
SB20260824185
and 5 more
#VU144770 - Authentication Bypass by Spoofing
CVE-2026-58162
CWE-290 High
No
No
9.2.15-1.el8, 9.2.15-1.el9, 10.1.4-1.fc43, 10.1.4-1.fc44 24.08.2026 SB20260824137
SB20260824184
SB20260824185
and 5 more
#VU144771 - Incorrect Comparison
CVE-2026-41920
CWE-697 High
No
No
9.2.15-1.el8, 9.2.15-1.el9, 10.1.4-1.fc43, 10.1.4-1.fc44 24.08.2026 SB20260824137
SB20260824184
SB20260824185
and 5 more
#VU144773 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling')
CVE-2026-58153
CWE-444 High
No
No
9.2.15-1.el8, 9.2.15-1.el9, 10.1.4-1.fc43, 10.1.4-1.fc44 24.08.2026 SB20260824137
SB20260824184
SB20260824185
and 5 more
#VU144774 - Improper Access Control
CVE-2026-58159
CWE-284 Medium
No
No
9.2.15-1.el8, 9.2.15-1.el9, 10.1.4-1.fc43, 10.1.4-1.fc44 24.08.2026 SB20260824137
SB20260824184
SB20260824185
and 5 more
#VU144777 - Stack-based buffer overflow
CVE-2026-58179
CWE-121 High
No
No
9.2.15-1.el8, 9.2.15-1.el9, 10.1.4-1.fc43, 10.1.4-1.fc44, 10.2.0-1.fc43, 10.2.0-1.fc44 24.08.2026 SB20260824137
SB20260824184
SB20260824185
and 7 more
#VU144778 - Deserialization of Untrusted Data
CVE-2026-58163
CWE-502 High
No
No
9.2.15-1.el8, 9.2.15-1.el9, 10.1.4-1.fc43, 10.1.4-1.fc44 24.08.2026 SB20260824137
SB20260824184
SB20260824185
and 5 more
#VU144779 - Use After Free
CVE-2026-58164
CWE-416 Medium
No
No
9.2.15-1.el8, 9.2.15-1.el9, 10.1.4-1.fc43, 10.1.4-1.fc44, 10.2.0-1.fc43, 10.2.0-1.fc44 24.08.2026 SB20260824137
SB20260824184
SB20260824185
and 7 more
#VU144780 - Missing release of memory after effective lifetime
CVE-2026-58175
CWE-401 Medium
No
No
9.2.15-1.el8, 9.2.15-1.el9, 10.1.4-1.fc43, 10.1.4-1.fc44 24.08.2026 SB20260824137
SB20260824184
SB20260824185
and 5 more
#VU144781 - Server-Side Request Forgery (SSRF)
CVE-2026-58178
CWE-918 Medium
No
No
9.2.15-1.el8, 9.2.15-1.el9, 10.1.4-1.fc43, 10.1.4-1.fc44 24.08.2026 SB20260824137
SB20260824184
SB20260824185
and 5 more


Showing elements 1 - 20 out of 61