Improper access control in Apache Traffic Server - CVE-2026-58159
Published: August 24, 2026
Vulnerability details
The vulnerability allows a remote attacker to bypass access controls.
The vulnerability exists due to improper access control in remap/ACL when handling UDS listeners and ACL matching. A remote attacker can exploit ACL matching errors to bypass access controls.
The advisory specifically mentions bypass of IP access controls on UDS listeners.
Affected software
Fedora
trafficserver
How to mitigate CVE-2026-58159
trafficserver - addressed in versions 9.2.15-1.el8, 9.2.15-1.el9, 10.1.4-1.fc43, 10.1.4-1.fc44