Buffer overflow in Apache Traffic Server - CVE-2026-58186
Published: August 24, 2026
Vulnerability details
The vulnerability allows a remote attacker to corrupt memory or poison cached responses.
The vulnerability exists due to unsafe decoding in plugin: webp_transform when decoding content for transformation. A remote attacker can supply crafted input to corrupt memory or poison cached responses.
The plugin can serve mislabeled, cacheable degraded responses.
Affected software
Fedora
trafficserver
How to mitigate CVE-2026-58186
trafficserver - addressed in versions 9.2.15-1.el8, 9.2.15-1.el9, 10.1.4-1.fc43, 10.1.4-1.fc44, 10.2.0-1.fc43, 10.2.0-1.fc44