SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-58158

MEDIUM · CVSS 5.9 EPSS 0.34%

Source: NVD + CISA KEV + EPSS · Published 2026-07-29 · Last synced 2026-08-28

CyberRota Analysis

AI-Generated

Apache Traffic Server versions 8.0.0 to 8.1.9, 9.0.0 to 9.2.14, and 10.0.0 to 10.1.3 are vulnerable due to improper handling of PROXY protocol input, leading to potential stack overflow and port truncation issues. This vulnerability could allow an attacker to execute arbitrary code or crash the server, impacting availability and security. Organizations using affected versions should prioritize upgrading to versions 9.2.15 or 10.1.4 to mitigate this risk.

CVE
CVE-2026-58158
Severity
MEDIUM
CVSS
5.9
EPSS
0.34%
Apache

Original NVD Description

Apache Traffic Server mishandles PROXY protocol input, truncating ports and overflowing the stack. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.

Related CVEs

Other vulnerabilities affecting the same vendor(s)