Seven Critical Vulnerabilities in Apache Traffic Server (up to CVSS 10.0)
This text was generated using artificial intelligence (AI).Update July 29, 2026: In addition, CVE-2026-58154, CVE-2026-58155 (CVSS 9.2), and CVE-2026-58162 (CVSS 10.0) have been disclosed. All three vulnerabilities affect the same version ranges and have been fixed in versions 9.2.15 and 10.1.4. See below for details.
On July 29, 2026, the Apache Software Foundation published an advisory for the Apache Traffic Server describing seven critical vulnerabilities. Four of these vulnerabilities have a CVSS score of 10.0 classified as "critical." The vulnerabilities enable attacks such as request smuggling and the generation of certificates based on attacker-controlled inputs, which allow attackers to bypass security controls and compromise backend systems. Numerous versions of the widely used caching and proxy software are affected.
This isn't the first time the Apache Traffic Server has made headlines due to serious security vulnerabilities: Back in April 2026, the Apache Software Foundation issued an emergency advisory regarding CVE-2025-58136 (denial-of-service) and CVE-2025-65114 (request smuggling). The recurrence of request smuggling vulnerabilities underscores the need for continuous monitoring of this infrastructure component. (Source: Cybersecurity News, April 2026)
The Advisory from the Apache Software Foundation summarizes seven serious security vulnerabilities that can be exploited remotely by an attacker without authentication. The high severity stems from the low complexity of the attack combined with the potentially high impact on data confidentiality and integrity.
The reported vulnerabilities are:
CVE-2026-58150 (CVSS 10.0): The server rejects the Transfer Encoding-It does not remove headers from HTTP/2 requests, which enables downgrade request smuggling.
CVE-2026-57834 (CVSS 10.0): Another request-smuggling vulnerability that can be exploited through improperly formatted „chunked“ messages.
CVE-2026-33267 (CVSS 10.0): A vulnerability caused by insufficient input validation (Improper Input Validation) that allows unspecified, far-reaching attacks.
CVE-2026-58162 (CVSS 10.0): The Apache Traffic Server's certifier plugin generates certificates based on attacker-controlled client SNI values, which enables serious attacks on integrity and availability.
CVE-2026-41920 (CVSS 9.3): Improper access control, which can allow unauthorized access to protected resources.
CVE-2026-58154 (CVSS 9.2): A critical vulnerability that allows attackers to compromise the confidentiality and integrity of data.
CVE-2026-58155 (CVSS 9.2): Another critical vulnerability with a similar potential for compromising confidentiality and integrity.
Affected Systems and Patch Availability
The vulnerabilities affect different version ranges of the Apache Traffic Server—depending on the specific CVE. The following table provides an overview:
CVE
Affected Versions
Recommended Fix
CVE-2026-58150
8.0.0–8.1.9, 9.0.0–9.2.14, 10.0.0–10.1.3
9/2/15 or 10/1/4
CVE-2026-57834
8.0.0–8.1.9, 9.0.0–9.2.14, 10.0.0–10.1.3
9/2/15 or 10/1/4
CVE-2026-33267
9.2.0–9.2.14, 10.1.0–10.1.3
9/2/15 or 10/1/4
CVE-2026-41920
9.0.0–9.1.14, 10.0.0–10.1.3
9.1.15 or 10.1.4
CVE-2026-58154
8.0.0–8.1.9, 9.0.0–9.2.14, 10.0.0–10.1.3
9/2/15 or 10/1/4
CVE-2026-58155
8.0.0–8.1.9, 9.0.0–9.2.14, 10.0.0–10.1.3
9/2/15 or 10/1/4
CVE-2026-58162
8.0.0–8.1.9, 9.0.0–9.2.14, 10.0.0–10.1.3
9/2/15 or 10/1/4
Important: CVE-2026-33267 affects only the 9.2.x and 10.1.x branches—installations on 8.x or 9.0.x/9.1.x are not affected by this vulnerability. CVE-2026-41920 affects the 9.0.x/9.1.x branch; for these installations, the recommended fix path is 9.1.15 (not Feb. 9, 2015).
The patch situation poses a particular challenge. The advisory recommends upgrading to the following versions: 9.2.15 or 10.1.4. However, at the time this article was published, these versions were not yet listed on the Apache Project's official download page. This discrepancy between the announcement and the public availability of the patches creates operational uncertainty for administrators, who must actively monitor the status of the new releases.
CVE-2026-58154 and CVE-2026-58155: Additional Critical Vulnerabilities
The two additional vulnerabilities reported, CVE-2026-58154 and CVE-2026-58155, have a CVSS score of 9.2 classified as critical. Both vulnerabilities affect the same version ranges as CVE-2026-58150 and CVE-2026-57834 (8.0.0–8.1.9, 9.0.0–9.2.14, 10.0.0–10.1.3) and allow unauthenticated remote attackers to compromise the confidentiality and integrity of data. The attack vector is network-based (AV:N) with low attack complexity (AC:L), which makes exploitation easier.
These vulnerabilities have been fixed in the same patch versions as the other CVEs: 9.2.15 and 10.1.4. Administrators who install these versions will thereby close all seven vulnerabilities described in the advisory.
CVE-2026-58162: Certificate generation based on attacker-controlled inputs
CVE-2026-58162 has a CVSS score of 10.0 Rated as "maximum critical" and affects the certifier plugin of the Apache Traffic Server. The vulnerability allows attackers to generate certificates based on attacker-controlled client SNI (Server Name Indication) values. The attack vector is network-based (AV:N) with low attack complexity (AC:L); no authentication is required (PR:N) and no user interaction is necessary (UI:N). The impact on integrity (I:H) and availability (A:H) is high, while the impact on confidentiality is low (C:L). The scope is “Changed” (S:C), meaning that the vulnerability may have effects beyond the vulnerable component.
The vulnerability affects versions 8.0.0–8.1.9, 9.0.0–9.2.14, and 10.0.0–10.1.3 and is present in the versions 9.2.15 and 10.1.4 Fixed. Organizations using the certifier plugin should prioritize installing the patch, as the vulnerability enables serious attacks on the TLS infrastructure.
Recommended Steps
Given the high severity of these vulnerabilities, swift action is required. Companies should prioritize the following steps:
Identification of Affected Systems: Identify all instances of Apache Traffic Server in your external infrastructure, including systems in shadow IT.
Version Check: Compare the installed versions with the CVE-specific table above to assess the immediate risk. Pay particular attention to the branch (8.x, 9.1.x, 9.2.x, 10.x), as the affected areas vary depending on the CVE.
Upgrade Soon: Plan and perform the upgrade to the corrected versions as soon as they are confirmed to be stable and available.
DACH Relevance and Regulatory Context
For organizations in Germany, Austria, and Switzerland, these vulnerabilities have specific regulatory implications. Operators of critical infrastructure (KRITIS) that use the Apache Traffic Server as a proxy or caching component are subject to the obligations of the NIS 2 Directive and must report security incidents immediately. If any of the vulnerabilities are actively exploited and personal data is affected, the reporting obligation under GDPR Article 33 also applies, requiring notification to the competent data protection authority within 72 hours. Companies should therefore ensure that their patching processes and incident response procedures are designed to meet these time requirements.
Creating Visibility into Vulnerabilities and the Supply Chain
Vulnerabilities in widely used software such as the Apache Traffic Server highlight two key challenges for corporate cybersecurity: the lack of transparency regarding a company’s own externally accessible IT infrastructure and the risks posed by software used by service providers.
An External Attack Surface Management (EASM) solution like LocateRisk helps organizations continuously monitor their attack surface. The platform identifies publicly accessible services such as the Apache Traffic Server—including forgotten subdomains, shadow IT systems, and untracked cloud assets—and enables security teams to quickly verify where potentially vulnerable software is being used within their organization. This forms the basis for a rapid and targeted response to new security alerts.
At the same time, Continuous Vendor Risk Management (C-VRM) addresses supply chain risk. Since suppliers and partners may also use the Apache Traffic Server, it is crucial to assess their security posture. C-VRM solutions automatically check the external security of third-party providers and issue alerts if their security level drops due to critical vulnerabilities. This allows for proactive management of supply chain risks—especially in light of recurring patterns such as the recent request-smuggling vulnerabilities in the Apache Traffic Server.
Apache Traffic Server is a high-performance, open-source proxy and caching software developed by the Apache Software Foundation. It is used by companies, CDN operators, and data centers to manage and accelerate HTTP traffic. Because of its exposed position between clients and backend systems, it is an attractive target for attacks—vulnerabilities can allow attackers to bypass security controls and gain access to internal systems.
The affected versions vary depending on the CVE. CVE-2026-58150, CVE-2026-57834, CVE-2026-58154, CVE-2026-58155, and CVE-2026-58162 affect versions 8.0.0–8.1.9, 9.0.0–9.2.14, and 10.0.0–10.1.3. CVE-2026-33267 affects only versions 9.2.0–9.2.14 and 10.1.0–10.1.3. CVE-2026-41920 affects versions 9.0.0–9.1.14 and 10.0.0–10.1.3. Administrators should check their respective branch and select the CVE-specific fix path.
The Apache Software Foundation's advisory recommends upgrading to version 9.2.15 or 10.1.4. For installations in the 9.0.x/9.1.x branch, the target fix for CVE-2026-41920 is 9.1.15. As of the publication of this article, the new versions were not yet listed on the official download page. Administrators should check the Announcements from the Apache Software Foundation actively monitor to confirm the availability of the patches.
As of July 29, 2026. This article is intended for general informational purposes only and does not constitute legal, security, or operational advice in specific cases. The security situation and patch availability may have changed since publication; the linked vendor advisory is always authoritative. Despite careful research, we do not guarantee that the information is up-to-date, accurate, or complete.
CVE Quick Check
In just a few minutes, check whether there are any indications of a current CVE on your externally visible attack surface.
A rough estimate in just a few minutes via email.
Learn more during a free consultation with a LocateRisk consultant.
You'll receive this by email
companyYour Company, LLC
Verified CVECVE-2024-3094
Passive Assessment
Information About the CVENotes found
Want to find out more, book a demo or simply exchange ideas? We look forward to hearing from you!
We use cookies to optimize our website and our service.
Functional
Always active
Technical storage or access is strictly necessary for the lawful purpose of enabling the use of a particular service expressly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a message over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that have not been requested by the subscriber or user.
Statistics
The technical storage or access, which is carried out exclusively for statistical purposes.Technical storage or access used solely for anonymous statistical purposes. Without a subpoena, the voluntary consent of your Internet service provider, or additional records from third parties, information stored or accessed for this purpose alone generally cannot be used to identify you.
Marketing
Technical storage or access is necessary to create user profiles, to send advertisements, or to track the user on a website or across multiple websites for similar marketing purposes.