Use-after-free in Apache Traffic Server - CVE-2026-58164
Published: August 24, 2026
Vulnerability details
The vulnerability allows a remote attacker to execute code using freed memory or cause a denial of service.
The vulnerability exists due to use-after-free in remap config when handling remap configuration lifetime and time-of-check/time-of-use conditions. A remote attacker can trigger remap configuration handling to execute code using freed memory or cause a denial of service.
Affected software
Fedora
trafficserver
How to mitigate CVE-2026-58164
trafficserver - addressed in versions 9.2.15-1.el8, 9.2.15-1.el9, 10.1.4-1.fc43, 10.1.4-1.fc44, 10.2.0-1.fc43, 10.2.0-1.fc44