Out-of-bounds write in Apache Traffic Server - CVE-2026-58154

 

Out-of-bounds write in Apache Traffic Server - CVE-2026-58154

Published: August 24, 2026


Vulnerability identifier: #VU144763
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-58154
CWE-ID: CWE-787
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to corrupt memory or execute arbitrary code.

The vulnerability exists due to out-of-bounds write in header parsing (MIME) when parsing MIME and HTTP headers. A remote attacker can send a specially crafted request to corrupt memory or execute arbitrary code.

The advisory also mentions integer overflow conditions in the same parsing logic.


Affected software

Apache Traffic Server
Fedora
trafficserver

How to mitigate CVE-2026-58154

Install security update from vendor's website.

Apache Traffic Server - addressed in versions 9.2.14, 10.1.3
trafficserver - addressed in versions 9.2.15-1.el8, 9.2.15-1.el9, 10.1.4-1.fc43, 10.1.4-1.fc44

External References

Related Security Bulletins