Stack-based buffer overflow in Apache Traffic Server - CVE-2026-58179
Published: August 24, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service or execute arbitrary code.
The vulnerability exists due to stack-based buffer overflow in plugin: regex_remap when processing substitution input. A remote attacker can send crafted substitution input to cause a denial of service or execute arbitrary code.
The advisory also mentions integer overflow conditions.
Affected software
Fedora
trafficserver
How to mitigate CVE-2026-58179
trafficserver - addressed in versions 9.2.15-1.el8, 9.2.15-1.el9, 10.1.4-1.fc43, 10.1.4-1.fc44, 10.2.0-1.fc43, 10.2.0-1.fc44