Known vulnerabilities in trafficserver - page 2

Software: trafficserver
Software CPE: cpe:2.3:o:fedoraproject:trafficserver:*:*:*:*:*:fedora:*:*
Total vulnerabilities: 61
Public exploits: 1
Known exploited (KEV): 1
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting trafficserver trafficserver is affected by 61 known vulnerabilities: 18 high, 41 medium, 2 low Critical High Medium Low

Vulnerabilities (61)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU144901 - Improper control of a resource through its lifetime
CVE-2026-65100
CWE-664 Medium
No
No
9.2.15-1.el8, 9.2.15-1.el9, 10.1.4-1.fc43, 10.1.4-1.fc44 24.08.2026 SB20260824179
SB20260824184
SB20260824185
and 5 more
#VU144902 - Improper Certificate Validation
CVE-2026-65325
CWE-295 High
No
No
9.2.15-1.el8, 9.2.15-1.el9, 10.1.4-1.fc43, 10.1.4-1.fc44 24.08.2026 SB20260824179
SB20260824184
SB20260824185
and 5 more
#VU144783 - Resource exhaustion
CVE-2026-58181
CWE-400 Medium
No
No
9.2.15-1.el8, 9.2.15-1.el9, 10.1.4-1.fc43, 10.1.4-1.fc44 24.08.2026 SB20260824137
SB20260824184
SB20260824185
and 5 more
#VU144784 - Memory corruption
CVE-2026-58186
CWE-119 High
No
No
9.2.15-1.el8, 9.2.15-1.el9, 10.1.4-1.fc43, 10.1.4-1.fc44, 10.2.0-1.fc43, 10.2.0-1.fc44 24.08.2026 SB20260824137
SB20260824184
SB20260824185
and 7 more
#VU144785 - Server-Side Request Forgery (SSRF)
CVE-2026-58189
CWE-918 Medium
No
No
9.2.15-1.el8, 9.2.15-1.el9, 10.1.4-1.fc43, 10.1.4-1.fc44 24.08.2026 SB20260824137
SB20260824184
SB20260824185
and 5 more
#VU144790 - Improper input validation
CVE-2026-58183
CWE-20 Medium
No
No
9.2.15-1.el8, 9.2.15-1.el9, 10.1.4-1.fc43, 10.1.4-1.fc44, 10.2.0-1.fc43, 10.2.0-1.fc44 24.08.2026 SB20260824137
SB20260824184
SB20260824185
and 7 more
#VU144791 - Use After Free
CVE-2026-58185
CWE-416 Medium
No
No
9.2.15-1.el8, 9.2.15-1.el9, 10.1.4-1.fc43, 10.1.4-1.fc44, 10.2.0-1.fc43, 10.2.0-1.fc44 24.08.2026 SB20260824137
SB20260824184
SB20260824185
and 7 more
#VU144793 - Out-of-bounds write
CVE-2026-58187
CWE-787 Medium
No
No
9.2.15-1.el8, 9.2.15-1.el9, 10.1.4-1.fc43, 10.1.4-1.fc44 24.08.2026 SB20260824137
SB20260824184
SB20260824185
and 5 more
#VU144760 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling')
CVE-2026-33267
CWE-444 High
No
No
9.2.15-1.el8, 9.2.15-1.el9, 10.1.4-1.fc43, 10.1.4-1.fc44 24.08.2026 SB20260824137
SB20260824184
SB20260824185
and 5 more
#VU144761 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling')
CVE-2026-58150
CWE-444 High
No
No
9.2.15-1.el8, 9.2.15-1.el9, 10.1.4-1.fc43, 10.1.4-1.fc44 24.08.2026 SB20260824137
SB20260824184
SB20260824185
and 5 more
#VU144762 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling')
CVE-2026-58155
CWE-444 High
No
No
9.2.15-1.el8, 9.2.15-1.el9, 10.1.4-1.fc43, 10.1.4-1.fc44 24.08.2026 SB20260824137
SB20260824184
SB20260824185
and 5 more
#VU144763 - Out-of-bounds write
CVE-2026-58154
CWE-787 High
No
No
9.2.15-1.el8, 9.2.15-1.el9, 10.1.4-1.fc43, 10.1.4-1.fc44 24.08.2026 SB20260824137
SB20260824184
SB20260824185
and 5 more
#VU144764 - Session Fixation
CVE-2026-58157
CWE-384 Medium
No
No
9.2.15-1.el8, 9.2.15-1.el9, 10.1.4-1.fc43, 10.1.4-1.fc44, 10.2.0-1.fc43, 10.2.0-1.fc44 24.08.2026 SB20260824137
SB20260824184
SB20260824185
and 7 more
#VU144765 - Permissive Regular Expression
CVE-2026-22068
CWE-625 High
No
No
9.2.15-1.el8, 9.2.15-1.el9, 10.1.4-1.fc43, 10.1.4-1.fc44, 10.2.0-1.fc43 24.08.2026 SB20260824137
SB20260824184
SB20260824185
and 6 more
#VU144767 - Resource exhaustion
CVE-2026-58151
CWE-400 Medium
No
No
9.2.15-1.el8, 9.2.15-1.el9, 10.1.4-1.fc43, 10.1.4-1.fc44 24.08.2026 SB20260824137
SB20260824184
SB20260824185
and 5 more
#VU144768 - NULL Pointer Dereference
CVE-2026-58161
CWE-476 Medium
No
No
9.2.15-1.el8, 9.2.15-1.el9, 10.1.4-1.fc43, 10.1.4-1.fc44, 10.2.0-1.fc43, 10.2.0-1.fc44 24.08.2026 SB20260824137
SB20260824184
SB20260824185
and 7 more
#VU144772 - Improper Initialization
CVE-2026-58182
CWE-665 Medium
No
No
9.2.15-1.el8, 9.2.15-1.el9, 10.1.4-1.fc43, 10.1.4-1.fc44, 10.2.0-1.fc43, 10.2.0-1.fc44 24.08.2026 SB20260824137
SB20260824184
SB20260824185
and 7 more
#VU144775 - Memory corruption
CVE-2026-58184
CWE-119 Medium
No
No
9.2.15-1.el8, 9.2.15-1.el9, 10.1.4-1.fc43, 10.1.4-1.fc44 24.08.2026 SB20260824137
SB20260824184
SB20260824185
and 5 more
#VU144776 - Memory corruption
CVE-2026-58188
CWE-119 High
No
No
9.2.15-1.el8, 9.2.15-1.el9, 10.1.4-1.fc43, 10.1.4-1.fc44 24.08.2026 SB20260824137
SB20260824184
SB20260824185
and 5 more
#VU107429 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling')
CVE-2024-53868
CWE-444 Medium
No
No
9.2.10-1.el8, 9.2.10-1.el9, 9.2.10-1.fc40, 9.2.10-1.fc41, 10.0.5-1.fc42 14.04.2025 SB2025041439
SB2025041443
SB2025041444
and 6 more


Showing elements 21 - 40 out of 61