Skip to content

Apache Traffic Server: improper input validation

High8.2CVE-2026-58186 · Published Jul 29, 2026 · updated Oct 1, 2026

The Apache Traffic Server webp_transform plugin can decode unsafely and serve mislabeled, cacheable responses. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.11, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.

Affected versions

PackageAffectedFixed in
Apache Traffic Server
Product
>= 8.0.0, <= 8.1.11No fix yet
>= 9.0.0, <= 9.2.14No fix yet
>= 10.0.0, <= 10.1.3No fix yet
Details and references
CVSS 4.0
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Severity from
the vendor (its own CVE record or advisory)
Weakness
CWE-20

More Apache Software Foundation advisories

All Apache Software Foundation
Advisory
Apache Traffic Server: out-of-bounds write
High8.4Jul 29
Apache Traffic Server: server-side request forgery
High8.2Jul 29
Apache Traffic Server updates the HTTP/2 HPACK dynamic table before confirming...
Medium6.3Jul 29
Apache Traffic Server: stack buffer overflow
High8.2Jul 29
Apache Traffic Server: resource exhaustion
High8.2Jul 29
Apache Traffic Server: improper input validation
High8.2Jul 29

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.