SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-58185

MEDIUM · CVSS 5.9 EPSS 0.34%

Source: NVD + CISA KEV + EPSS · Published 2026-07-29 · Last synced 2026-08-28

CyberRota Analysis

AI-Generated

The Apache Traffic Server's intercept plugin is vulnerable to a use-after-free flaw, impacting versions 8.0.0 to 8.1.9, 9.0.0 to 9.2.14, and 10.0.0 to 10.1.3. This vulnerability could potentially allow an attacker to execute arbitrary code, leading to unauthorized access or service disruption. Organizations using affected versions should prioritize upgrading to versions 9.2.15 or 10.1.4 to mitigate the risk.

CVE
CVE-2026-58185
Severity
MEDIUM
CVSS
5.9
EPSS
0.34%
Apache

Original NVD Description

The Apache Traffic Server intercept plugin has a use-after-free. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.

Related CVEs

Other vulnerabilities affecting the same vendor(s)