Known vulnerabilities in trafficserver

Vendor: openEuler
Software: trafficserver
Software CPE: cpe:2.3:o:openeuler:trafficserver:*:*:*:*:*:openeuler:*:*
Total vulnerabilities: 61
Public exploits: 0
Known exploited (KEV): 0
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting trafficserver trafficserver is affected by 61 known vulnerabilities: 16 high, 44 medium, 1 low Critical High Medium Low

Vulnerabilities (61)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU144782 - Stack-based buffer overflow
CVE-2026-58180
CWE-121 Medium
No
No
9.2.15-1 24.08.2026 SB20260824137
SB20260824184
SB20260824185
and 5 more
#VU144783 - Resource exhaustion
CVE-2026-58181
CWE-400 Medium
No
No
9.2.15-1 24.08.2026 SB20260824137
SB20260824184
SB20260824185
and 5 more
#VU144787 - Out-of-bounds read
CVE-2026-58160
CWE-125 Medium
No
No
9.2.15-1 24.08.2026 SB20260824137
SB20260824184
SB20260824185
and 7 more
#VU144788 - Integer overflow
CVE-2026-58152
CWE-190 Medium
No
No
9.2.15-1 24.08.2026 SB20260824137
SB20260824184
SB20260824185
and 5 more
#VU144789 - Stack-based buffer overflow
CVE-2026-58158
CWE-121 Medium
No
No
9.2.15-1 24.08.2026 SB20260824137
SB20260824184
SB20260824185
and 7 more
#VU144792 - Improper input validation
CVE-2026-58156
CWE-20 Medium
No
No
9.2.15-1 24.08.2026 SB20260824137
SB20260824184
SB20260824185
and 5 more
#VU144762 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling')
CVE-2026-58155
CWE-444 High
No
No
9.2.15-1 24.08.2026 SB20260824137
SB20260824184
SB20260824185
and 5 more
#VU144763 - Out-of-bounds write
CVE-2026-58154
CWE-787 High
No
No
9.2.15-1 24.08.2026 SB20260824137
SB20260824184
SB20260824185
and 5 more
#VU144764 - Session Fixation
CVE-2026-58157
CWE-384 Medium
No
No
9.2.15-1 24.08.2026 SB20260824137
SB20260824184
SB20260824185
and 7 more
#VU144767 - Resource exhaustion
CVE-2026-58151
CWE-400 Medium
No
No
9.2.15-1 24.08.2026 SB20260824137
SB20260824184
SB20260824185
and 5 more
#VU144768 - NULL Pointer Dereference
CVE-2026-58161
CWE-476 Medium
No
No
9.2.15-1 24.08.2026 SB20260824137
SB20260824184
SB20260824185
and 7 more
#VU144770 - Authentication Bypass by Spoofing
CVE-2026-58162
CWE-290 High
No
No
9.2.15-1 24.08.2026 SB20260824137
SB20260824184
SB20260824185
and 5 more
#VU144772 - Improper Initialization
CVE-2026-58182
CWE-665 Medium
No
No
9.2.15-1 24.08.2026 SB20260824137
SB20260824184
SB20260824185
and 7 more
#VU144773 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling')
CVE-2026-58153
CWE-444 High
No
No
9.2.15-1 24.08.2026 SB20260824137
SB20260824184
SB20260824185
and 5 more
#VU144774 - Improper Access Control
CVE-2026-58159
CWE-284 Medium
No
No
9.2.15-1 24.08.2026 SB20260824137
SB20260824184
SB20260824185
and 5 more
#VU144777 - Stack-based buffer overflow
CVE-2026-58179
CWE-121 High
No
No
9.2.15-1 24.08.2026 SB20260824137
SB20260824184
SB20260824185
and 7 more
#VU144778 - Deserialization of Untrusted Data
CVE-2026-58163
CWE-502 High
No
No
9.2.15-1 24.08.2026 SB20260824137
SB20260824184
SB20260824185
and 5 more
#VU144779 - Use After Free
CVE-2026-58164
CWE-416 Medium
No
No
9.2.15-1 24.08.2026 SB20260824137
SB20260824184
SB20260824185
and 7 more
#VU144780 - Missing release of memory after effective lifetime
CVE-2026-58175
CWE-401 Medium
No
No
9.2.15-1 24.08.2026 SB20260824137
SB20260824184
SB20260824185
and 5 more
#VU144781 - Server-Side Request Forgery (SSRF)
CVE-2026-58178
CWE-918 Medium
No
No
9.2.15-1 24.08.2026 SB20260824137
SB20260824184
SB20260824185
and 5 more


Showing elements 1 - 20 out of 61