SEPTEMBER 20, 2026
Live Feed
Back to database
Case File

CVE-2026-58184

HIGH · CVSS 8.2 EPSS 0.35%

Source: NVD + CISA KEV + EPSS · Published 2026-07-29 · Last synced 2026-08-28

CyberRota Analysis

AI-Generated

The Apache Traffic Server's header_rewrite plugin is vulnerable to memory corruption and crashes during cookie operations and CIDR condition matching, affecting versions 8.0.0 to 8.1.9, 9.0.0 to 9.2.14, and 10.0.0 to 10.1.3. This high-severity vulnerability could lead to service disruptions, making it critical for organizations using affected versions to prioritize upgrading to versions 9.2.15 or 10.1.4 to mitigate risks.

CVE
CVE-2026-58184
Severity
HIGH
CVSS
8.2
EPSS
0.35%
Apache

Original NVD Description

The Apache Traffic Server header_rewrite plugin can crash or corrupt memory during cookie operations and CIDR condition matching. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.

Related CVEs

Other vulnerabilities affecting the same vendor(s)