Server-Side Request Forgery (SSRF) in Apache Traffic Server - CVE-2026-58178
Published: August 24, 2026
Vulnerability details
The vulnerability allows a remote attacker to perform server-side request forgery or cause a denial of service.
The vulnerability exists due to improper restriction of recursive processing and URL fetching in plugin: ESI when recursing and fetching attacker-controlled URLs. A remote attacker can supply crafted content to perform server-side request forgery or cause a denial of service.
The plugin can recurse without bound.
Affected software
Fedora
trafficserver
How to mitigate CVE-2026-58178
trafficserver - addressed in versions 9.2.15-1.el8, 9.2.15-1.el9, 10.1.4-1.fc43, 10.1.4-1.fc44