Seven Critical Vulnerabilities in Apache Traffic Server (up to CVSS 10.0)


This text was generated using artificial intelligence (AI).Update July 29, 2026: In addition, CVE-2026-58154, CVE-2026-58155 (CVSS 9.2), and CVE-2026-58162 (CVSS 10.0) have been disclosed. All three vulnerabilities affect the same version ranges and have been fixed in versions 9.2.15 and 10.1.4. See below for details.

On July 29, 2026, the Apache Software Foundation published an advisory for the Apache Traffic Server describing seven critical vulnerabilities. Four of these vulnerabilities have a CVSS score of 10.0 classified as "critical." The vulnerabilities enable attacks such as request smuggling and the generation of certificates based on attacker-controlled inputs, which allow attackers to bypass security controls and compromise backend systems. Numerous versions of the widely used caching and proxy software are affected.

This isn't the first time the Apache Traffic Server has made headlines due to serious security vulnerabilities: Back in April 2026, the Apache Software Foundation issued an emergency advisory regarding CVE-2025-58136 (denial-of-service) and CVE-2025-65114 (request smuggling). The recurrence of request smuggling vulnerabilities underscores the need for continuous monitoring of this infrastructure component. (Source: Cybersecurity News, April 2026)

Are my systems affected? Check now →