SEPTEMBER 20, 2026
Live Feed
Back to database
Case File

CVE-2026-22068

HIGH · CVSS 8.2 EPSS 0.41%

Source: NVD + CISA KEV + EPSS · Published 2026-07-29 · Last synced 2026-08-28

CyberRota Analysis

AI-Generated

A vulnerability in Apache Traffic Server allows for regular expressions without anchors, potentially leading to Denial of Service (DoS) attacks. This affects versions 10.0.X through 10.1.3 and 9.0.X through 9.2.14, making it critical for users operating these versions to prioritize upgrading to 9.2.15 or 10.1.4 to mitigate the risk. Organizations relying on Apache Traffic Server for their web traffic management should address this issue promptly to maintain service availability.

CVE
CVE-2026-22068
Severity
HIGH
CVSS
8.2
EPSS
0.41%
Apache

Original NVD Description

Regular Expression without Anchors vulnerability in Apache Traffic Server. This issue affects Apache Traffic Server: from 10.0.X through 10.1.3, from 9.0.X through 9.2.14. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fixes the issue.

Related CVEs

Other vulnerabilities affecting the same vendor(s)