Buffer overflow in Apache Traffic Server - CVE-2026-58186

 

Buffer overflow in Apache Traffic Server - CVE-2026-58186

Published: August 24, 2026


Vulnerability identifier: #VU144784
CSH Severity: High
CVSS v4: 8.8 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-58186
CWE-ID: CWE-119
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to corrupt memory or poison cached responses.

The vulnerability exists due to unsafe decoding in plugin: webp_transform when decoding content for transformation. A remote attacker can supply crafted input to corrupt memory or poison cached responses.

The plugin can serve mislabeled, cacheable degraded responses.


Affected software

Apache Traffic Server
Fedora
trafficserver

How to mitigate CVE-2026-58186

Install security update from vendor's website.

Apache Traffic Server - addressed in versions 9.2.14, 10.1.3
trafficserver - addressed in versions 9.2.15-1.el8, 9.2.15-1.el9, 10.1.4-1.fc43, 10.1.4-1.fc44, 10.2.0-1.fc43, 10.2.0-1.fc44

External References

Related Security Bulletins