Known vulnerabilities in trafficserver - page 2
Vendor:
Fedoraproject
Software:
trafficserver
Software CPE:
cpe:2.3:o:fedoraproject:trafficserver:*:*:*:*:*:fedora:*:*
Website:
https://getfedora.org/
Total vulnerabilities:
61
Public exploits:
1
Known exploited (KEV):
1
Highest CVSSv4 Score:
9.3
Breakdown by Severity Chart
10.2.0-1.fc43
10.2.0-1.fc44
10.1.4-1.fc43
10.1.4-1.fc44
9.2.15-1.el9
9.2.15-1.el8
10.1.3-1.fc43
10.1.3-1.fc44
9.2.14-1.el9
9.2.14-1.el8
10.1.2-1.fc43
10.1.2-1.fc44
10.1.2-1.fc42
9.2.13-1.el9
9.2.13-1.el8
5.3.0-1.fc21
5.3.0-1.fc22
5.3.0-1.el6
5.3.0-1.el7
9.2.10-1.fc40
9.2.10-1.el9
10.0.5-1.fc42
9.2.10-1.fc41
9.2.10-1.el8
9.2.9-1.fc40
9.2.9-1.el9
9.2.9-1.el8
9.2.9-1.fc41
9.1.4-1.fc36
9.1.4-1.el7
9.1.4-1.fc37
9.1.4-1.el8
9.1.4-1.el9
9.1.3-1.el9
9.1.3-1.el8
9.1.3-1.el7
9.1.3-1.fc35
9.1.3-1.fc36
9.2.6-2.fc39
9.2.6-2.fc40
9.2.6-2.fc41
9.2.6-2.el9
9.2.6-2.el8
9.2.5-1.el8
9.2.5-1.fc40
9.2.5-1.el9
9.2.5-1.fc39
9.2.4-1.fc39
9.2.4-1.fc38
9.2.4-1.fc40
9.2.4-1.el8
9.2.4-1.el9
9.2.4-1.el7
9.2.3-1.el7
9.2.3-1.el8
9.2.3-1.el9
9.2.3-1.fc37
9.2.3-1.fc39
9.2.3-1.fc38
9.2.1-1.el7
9.2.1-1.fc38
9.2.1-1.fc37
9.2.1-1.el8
9.2.1-1.el9
Vulnerabilities (61)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU144901 - Improper control of a resource through its lifetime CVE-2026-65100 |
CWE-664 | Medium | 9.2.15-1.el8, 9.2.15-1.el9, 10.1.4-1.fc43, 10.1.4-1.fc44 | 24.08.2026 |
SB20260824179 SB20260824184 SB20260824185 and 5 more |
||
| #VU144902 - Improper Certificate Validation CVE-2026-65325 |
CWE-295 | High | 9.2.15-1.el8, 9.2.15-1.el9, 10.1.4-1.fc43, 10.1.4-1.fc44 | 24.08.2026 |
SB20260824179 SB20260824184 SB20260824185 and 5 more |
||
| #VU144783 - Resource exhaustion CVE-2026-58181 |
CWE-400 | Medium | 9.2.15-1.el8, 9.2.15-1.el9, 10.1.4-1.fc43, 10.1.4-1.fc44 | 24.08.2026 |
SB20260824137 SB20260824184 SB20260824185 and 5 more |
||
| #VU144784 - Memory corruption CVE-2026-58186 |
CWE-119 | High | 9.2.15-1.el8, 9.2.15-1.el9, 10.1.4-1.fc43, 10.1.4-1.fc44, 10.2.0-1.fc43, 10.2.0-1.fc44 | 24.08.2026 |
SB20260824137 SB20260824184 SB20260824185 and 7 more |
||
| #VU144785 - Server-Side Request Forgery (SSRF) CVE-2026-58189 |
CWE-918 | Medium | 9.2.15-1.el8, 9.2.15-1.el9, 10.1.4-1.fc43, 10.1.4-1.fc44 | 24.08.2026 |
SB20260824137 SB20260824184 SB20260824185 and 5 more |
||
| #VU144790 - Improper input validation CVE-2026-58183 |
CWE-20 | Medium | 9.2.15-1.el8, 9.2.15-1.el9, 10.1.4-1.fc43, 10.1.4-1.fc44, 10.2.0-1.fc43, 10.2.0-1.fc44 | 24.08.2026 |
SB20260824137 SB20260824184 SB20260824185 and 7 more |
||
| #VU144791 - Use After Free CVE-2026-58185 |
CWE-416 | Medium | 9.2.15-1.el8, 9.2.15-1.el9, 10.1.4-1.fc43, 10.1.4-1.fc44, 10.2.0-1.fc43, 10.2.0-1.fc44 | 24.08.2026 |
SB20260824137 SB20260824184 SB20260824185 and 7 more |
||
| #VU144793 - Out-of-bounds write CVE-2026-58187 |
CWE-787 | Medium | 9.2.15-1.el8, 9.2.15-1.el9, 10.1.4-1.fc43, 10.1.4-1.fc44 | 24.08.2026 |
SB20260824137 SB20260824184 SB20260824185 and 5 more |
||
| #VU144760 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') CVE-2026-33267 |
CWE-444 | High | 9.2.15-1.el8, 9.2.15-1.el9, 10.1.4-1.fc43, 10.1.4-1.fc44 | 24.08.2026 |
SB20260824137 SB20260824184 SB20260824185 and 5 more |
||
| #VU144761 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') CVE-2026-58150 |
CWE-444 | High | 9.2.15-1.el8, 9.2.15-1.el9, 10.1.4-1.fc43, 10.1.4-1.fc44 | 24.08.2026 |
SB20260824137 SB20260824184 SB20260824185 and 5 more |
||
| #VU144762 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') CVE-2026-58155 |
CWE-444 | High | 9.2.15-1.el8, 9.2.15-1.el9, 10.1.4-1.fc43, 10.1.4-1.fc44 | 24.08.2026 |
SB20260824137 SB20260824184 SB20260824185 and 5 more |
||
| #VU144763 - Out-of-bounds write CVE-2026-58154 |
CWE-787 | High | 9.2.15-1.el8, 9.2.15-1.el9, 10.1.4-1.fc43, 10.1.4-1.fc44 | 24.08.2026 |
SB20260824137 SB20260824184 SB20260824185 and 5 more |
||
| #VU144764 - Session Fixation CVE-2026-58157 |
CWE-384 | Medium | 9.2.15-1.el8, 9.2.15-1.el9, 10.1.4-1.fc43, 10.1.4-1.fc44, 10.2.0-1.fc43, 10.2.0-1.fc44 | 24.08.2026 |
SB20260824137 SB20260824184 SB20260824185 and 7 more |
||
| #VU144765 - Permissive Regular Expression CVE-2026-22068 |
CWE-625 | High | 9.2.15-1.el8, 9.2.15-1.el9, 10.1.4-1.fc43, 10.1.4-1.fc44, 10.2.0-1.fc43 | 24.08.2026 |
SB20260824137 SB20260824184 SB20260824185 and 6 more |
||
| #VU144767 - Resource exhaustion CVE-2026-58151 |
CWE-400 | Medium | 9.2.15-1.el8, 9.2.15-1.el9, 10.1.4-1.fc43, 10.1.4-1.fc44 | 24.08.2026 |
SB20260824137 SB20260824184 SB20260824185 and 5 more |
||
| #VU144768 - NULL Pointer Dereference CVE-2026-58161 |
CWE-476 | Medium | 9.2.15-1.el8, 9.2.15-1.el9, 10.1.4-1.fc43, 10.1.4-1.fc44, 10.2.0-1.fc43, 10.2.0-1.fc44 | 24.08.2026 |
SB20260824137 SB20260824184 SB20260824185 and 7 more |
||
| #VU144772 - Improper Initialization CVE-2026-58182 |
CWE-665 | Medium | 9.2.15-1.el8, 9.2.15-1.el9, 10.1.4-1.fc43, 10.1.4-1.fc44, 10.2.0-1.fc43, 10.2.0-1.fc44 | 24.08.2026 |
SB20260824137 SB20260824184 SB20260824185 and 7 more |
||
| #VU144775 - Memory corruption CVE-2026-58184 |
CWE-119 | Medium | 9.2.15-1.el8, 9.2.15-1.el9, 10.1.4-1.fc43, 10.1.4-1.fc44 | 24.08.2026 |
SB20260824137 SB20260824184 SB20260824185 and 5 more |
||
| #VU144776 - Memory corruption CVE-2026-58188 |
CWE-119 | High | 9.2.15-1.el8, 9.2.15-1.el9, 10.1.4-1.fc43, 10.1.4-1.fc44 | 24.08.2026 |
SB20260824137 SB20260824184 SB20260824185 and 5 more |
||
| #VU107429 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') CVE-2024-53868 |
CWE-444 | Medium | 9.2.10-1.el8, 9.2.10-1.el9, 9.2.10-1.fc40, 9.2.10-1.fc41, 10.0.5-1.fc42 | 14.04.2025 |
SB2025041439 SB2025041443 SB2025041444 and 6 more |
Showing elements 21 - 40 out of 61