SEPTEMBER 20, 2026
Live Feed
Back to database
Case File

CVE-2026-58177

HIGH · CVSS 8.1 EPSS 0.33%

Source: NVD + CISA KEV + EPSS · Published 2026-07-29 · Last synced 2026-08-28

CyberRota Analysis

AI-Generated

Apache Traffic Server versions 10.0.0 through 10.1.3 are vulnerable to out-of-bounds writes, path traversal, and use-after-free errors, which could lead to potential data corruption or unauthorized access. Organizations using these versions should prioritize upgrading to 10.1.4 to mitigate the risks associated with these vulnerabilities. Immediate action is essential for those managing critical infrastructure relying on Apache Traffic Server.

CVE
CVE-2026-58177
Severity
HIGH
CVSS
8.1
EPSS
0.33%
Apache

Original NVD Description

The Apache Traffic Server Cripts framework has out-of-bounds writes, path traversal, and use-after-free errors. This issue affects Apache Traffic Server: from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 10.1.4, which fix the issue.

Related CVEs

Other vulnerabilities affecting the same vendor(s)