{"schema_version":"1.7.2","id":"OESA-2026-3310","modified":"2026-08-07T02:46:32Z","published":"2026-08-07T02:46:32Z","upstream":["CVE-2026-22068","CVE-2026-24033","CVE-2026-33267","CVE-2026-33930","CVE-2026-41920","CVE-2026-57834","CVE-2026-58150","CVE-2026-58151","CVE-2026-58152","CVE-2026-58153","CVE-2026-58154","CVE-2026-58155","CVE-2026-58156","CVE-2026-58157","CVE-2026-58158","CVE-2026-58159","CVE-2026-58160","CVE-2026-58161","CVE-2026-58162","CVE-2026-58163","CVE-2026-58164","CVE-2026-58175","CVE-2026-58178","CVE-2026-58179","CVE-2026-58180","CVE-2026-58181","CVE-2026-58182","CVE-2026-58183","CVE-2026-58184","CVE-2026-58185","CVE-2026-58186","CVE-2026-58187","CVE-2026-58188","CVE-2026-58189","CVE-2026-59173","CVE-2026-65100","CVE-2026-65324","CVE-2026-65325"],"summary":"trafficserver security update","details":"Apache Traffic Server is an OpenSource HTTP / HTTPS / HTTP/2 / QUIC reverse, forward and transparent proxy and cache.\r\n\r\nSecurity Fix(es):\n\nRegular Expression without Anchors vulnerability in Apache Traffic Server.\n\nThis issue affects Apache Traffic Server: from 10.0.X through 10.1.3, from 9.0.X through 9.2.14.\n\nUsers are recommended to upgrade to version 9.2.15 or 10.1.4, which fixes the issue.(CVE-2026-22068)\n\nInconsistent Interpretation of HTTP Requests (&apos;HTTP Request/Response Smuggling&apos;) vulnerability in Apache Traffic Server.\n\nThis issue affects Apache Traffic Server: from 10.0.0 through 10.1.3, from 9.0.0 through 9.2.14.\n\nUsers are recommended to upgrade to version 9.2.15 or 10.1.4, which fixes the issue.(CVE-2026-24033)\n\nImproper Input Validation vulnerability in Apache Traffic Server.\n\nThis issue affects Apache Traffic Server: from 9.2.0 through 9.2.14, from 10.1.0 through 10.1.3.\n\nUsers are recommended to upgrade to version 9.2.15 or 10.1.4, which fixes the issue.(CVE-2026-33267)\n\nApache Traffic Server copies the client Host header into a fixed-size stack buffer without a bound during redirect handling, so an over-long Host header overflows the stack when redirect following is enabled.\n\nThis issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3.\n\nUsers are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.(CVE-2026-33930)\n\nImproper Access Control vulnerability in Apache Traffic Server.\n\nThis issue affects Apache Traffic Server: from 9.0.0 through 9.1.14, from 10.0.0 through 10.1.3.\n\nUsers are recommended to upgrade to version 9.1.15 or 10.1.4, which fixes the issue.(CVE-2026-41920)\n\nApache Traffic Server allows request smuggling if chunked messages are malformed.\n\nThis issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3.\n\nUsers are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.(CVE-2026-57834)\n\nApache Traffic Server does not reject Transfer-Encoding in HTTP/2 requests, allowing downgrade request smuggling.\n\nThis issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3.\n\nUsers are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.(CVE-2026-58150)\n\nApache Traffic Server can be crashed or driven to resource exhaustion by abusive HTTP/2 framing and flow-control.\n\nThis issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3.\n\nUsers are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.(CVE-2026-58151)\n\nApache Traffic Server mishandles integers while decoding HPACK/XPACK headers, corrupting memory.\n\nThis issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3.\n\nUsers are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.(CVE-2026-58152)\n\nApache Traffic Server forwards HTTP/2 origin trailers to HTTP/1 clients without proper chunked framing when converting HTTP/2 to HTTP/1.\n\nThis issue affects Apache Traffic Server: from 10.0.0 through 10.1.3.\n\nUsers are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.(CVE-2026-58153)\n\nApache Traffic Server can write out of bounds or overflow integers while parsing MIME and HTTP headers.\n\nThis issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3.\n\nUsers are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.(CVE-2026-58154)\n\nApache Traffic Server truncates over-long header names, allowing header aliasing, request smuggling, and policy bypass.\n\nThis issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3.\n\nUsers are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.(CVE-2026-58155)\n\nApache Traffic Server mis-parses ports in URLs and userinfo, allowing port-based access-control bypass.\n\nThis issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3.\n\nUsers are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.(CVE-2026-58156)\n\nApache Traffic Server can reuse server sessions and tunnels improperly, exposing data across client connections.\n\nThis issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3.\n\nUsers are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.(CVE-2026-58157)\n\nApache Traffic Server mishandles PROXY protocol input, truncating ports and overflowing the stack.\n\nThis issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3.\n\nUsers are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.(CVE-2026-58158)\n\nApache Traffic Server can bypass IP access controls on UDS listeners and through ACL matching errors.\n\nThis issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3.\n\nUsers are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.(CVE-2026-58159)\n\nApache Traffic Server reads out of bounds while parsing DNS answers.\n\nThis issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3.\n\nUsers are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.(CVE-2026-58160)\n\nApache Traffic Server can crash from null dereferences and dangling references in TLS and SNI handling.\n\nThis issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3.\n\nUsers are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.(CVE-2026-58161)\n\nThe Apache Traffic Server certifier plugin generates certificates based on attacker-controlled client SNI.\n\nThis issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3.\n\nUsers are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.(CVE-2026-58162)\n\nApache Traffic Server mishandles on-disk cache fields and object lifetimes, corrupting state or crashing.\n\nThis issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3.\n\nUsers are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.(CVE-2026-58163)\n\nApache Traffic Server has use-after-free and time-of-check/time-of-use errors in remap configuration handling.\n\nThis issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3.\n\nUsers are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.(CVE-2026-58164)\n\nApache Traffic Server leaks memory when handling HostDB SRV records.\n\nThis issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3.\n\nUsers are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.(CVE-2026-58175)\n\nThe Apache Traffic Server ESI plugin can recurse without bound and fetch attacker-controlled URLs.\n\nThis issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3.\n\nUsers are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.(CVE-2026-58178)\n\nThe Apache Traffic Server regex_remap plugin overflows the stack and integers from substitution input.\n\nThis issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3.\n\nUsers are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.(CVE-2026-58179)\n\nThe Apache Traffic Server txn_box plugin overflows the stack from attacker-controlled input.\n\nThis issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3.\n\nUsers are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.(CVE-2026-58180)\n\nThe Apache Traffic Server uri_signing and url_sig plugins can exhaust the stack or crash on attacker input.\n\nThis issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3.\n\nUsers are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.(CVE-2026-58181)\n\nThe Apache Traffic Server ts_lua plugin mishandles initialization, transform context, and per-instance state.\n\nThis issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3.\n\nUsers are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.(CVE-2026-58182)\n\nThe Apache Traffic Server prefetch plugin can crash when processing attacker-influenced input.\n\nThis issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3.\n\nUsers are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.(CVE-2026-58183)\n\nThe Apache Traffic Server header_rewrite plugin can crash or corrupt memory during cookie operations and CIDR condition matching.\n\nThis issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3.\n\nUsers are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.(CVE-2026-58184)\n\nThe Apache Traffic Server intercept plugin has a use-after-free.\n\nThis issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3.\n\nUsers are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.(CVE-2026-58185)\n\nThe Apache Traffic Server webp_transform plugin can decode unsafely and serve mislabeled, cacheable responses.\n\nThis issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3.\n\nUsers are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.(CVE-2026-58186)\n\nThe Apache Traffic Server multiplexer plugin overruns its chunk-decode buffer on upstream input, enabling denial of service.\n\nThis issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3.\n\nUsers are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.(CVE-2026-58187)\n\nSeveral Apache Traffic Server experimental plugins have memory-safety and limit-bypass errors.\n\nThis issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3.\n\nUsers are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.(CVE-2026-58188)\n\nApache Traffic Server allows redirect-limit bypass when plugins reset the retry counter, enabling SSRF amplification.\n\nThis issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3.\n\nUsers are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.(CVE-2026-58189)\n\nUncontrolled Resource Consumption vulnerability in Apache Traffic Server.\n\nThis issue affects Apache Traffic Server: from 9.0.0 through 9.1.13, from 10.0.0 through 10.1.2.\n\nUsers are recommended to upgrade to version 9.1.14 or 10.1.3, which fixes the issue.(CVE-2026-59173)\n\nApache Traffic Server updates the HTTP/2 HPACK dynamic table before confirming the header block encoded successfully, so an encode failure leaves the encoder out of sync with the peer decoder and corrupts subsequent header blocks on the connection.\n\nThis issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3.\n\nUsers are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.(CVE-2026-65100)\n\nApache Traffic Server drops the per-stream buffer cap when dechunking HTTP/2 or HTTP/3 responses, letting a slow client exhaust server memory.\n\nThis issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3.\n\nUsers are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.(CVE-2026-65324)\n\nApache Traffic Server reuses multiplexed HTTP/2 origin connections without verifying the server certificate covers the new request hostname.\n\nThis issue affects Apache Traffic Server: from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3.\n\nUsers are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.(CVE-2026-65325)","affected":[{"package":{"ecosystem":"openEuler:24.03-LTS-SP4","name":"trafficserver","purl":"pkg:rpm/openEuler/trafficserver&distro=openEuler-24.03-LTS-SP4"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"9.2.15-1.oe2403sp4"}]}],"ecosystem_specific":{"aarch64":["trafficserver-9.2.15-1.oe2403sp4.aarch64.rpm","trafficserver-debuginfo-9.2.15-1.oe2403sp4.aarch64.rpm","trafficserver-debugsource-9.2.15-1.oe2403sp4.aarch64.rpm","trafficserver-devel-9.2.15-1.oe2403sp4.aarch64.rpm","trafficserver-perl-9.2.15-1.oe2403sp4.aarch64.rpm"],"src":["trafficserver-9.2.15-1.oe2403sp4.src.rpm"],"x86_64":["trafficserver-9.2.15-1.oe2403sp4.x86_64.rpm","trafficserver-debuginfo-9.2.15-1.oe2403sp4.x86_64.rpm","trafficserver-debugsource-9.2.15-1.oe2403sp4.x86_64.rpm","trafficserver-devel-9.2.15-1.oe2403sp4.x86_64.rpm","trafficserver-perl-9.2.15-1.oe2403sp4.x86_64.rpm"]}}],"references":[{"type":"ADVISORY","url":"https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-3310"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-22068"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-24033"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-33267"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-33930"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-41920"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-57834"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-58150"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-58151"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-58152"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-58153"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-58154"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-58155"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-58156"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-58157"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-58158"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-58159"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-58160"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-58161"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-58162"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-58163"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-58164"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-58175"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-58178"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-58179"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-58180"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-58181"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-58182"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-58183"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-58184"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-58185"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-58186"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-58187"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-58188"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-58189"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-59173"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-65100"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-65324"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-65325"}],"severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"}],"database_specific":{"severity":"Critical"}}
