#1143062 trafficserver: CVE-2026-22068 CVE-2026-24033 CVE-2026-33267 CVE-2026-33930 CVE-2026-41920 CVE-2026-57834 CVE-2026-58150 CVE-2026-58151 CVE-2026-58152 CVE-2026-58153 CVE-2026-58154 CVE-2026-58155 CVE-2026-58156 CVE-2026-58157 CVE-2026-58158 CVE-2026-58159 CVE-2026-58160 CVE-2026-58161 CVE-2026-58162 CVE-2026-58163 CVE-2026-58164 CVE-2026-58175 CVE-2026-58177 CVE-2026-58178 CVE-2026-58179 CVE-2026-58180 CVE-2026-58181 CVE-2026-58182 CVE-2026-58183 CVE-2026-58184 CVE-2026-58185 CVE-2026-58186 CVE-2026-58187 CVE-2026-58188 CVE-2026-58189 CVE-2026-65100 CVE-2026-65324 CVE-2026-65325

Package:
src:trafficserver
Source:
src:trafficserver
Submitter:
Salvatore Bonaccorso
Date:
2026-09-21 13:45:07 UTC
Severity:
normal
Tags:
#1143062#5
Date:
2026-07-30 04:57:49 UTC
From:
To:
Hi,

The following vulnerabilities were published for trafficserver.

CVE-2026-22068[0]:
| Regular Expression without Anchors vulnerability in Apache Traffic
| Server.  This issue affects Apache Traffic Server: from 10.0.X
| through 10.1.3, from 9.0.X through 9.2.14.  Users are recommended to
| upgrade to version 9.2.15 or 10.1.4, which fixes the issue.


CVE-2026-24033[1]:
| Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response
| Smuggling') vulnerability in Apache Traffic Server.  This issue
| affects Apache Traffic Server: from 10.0.0 through 10.1.3, from
| 9.0.0 through 9.2.14.  Users are recommended to upgrade to version
| 9.2.15 or 10.1.4, which fixes the issue.


CVE-2026-33267[2]:
| Improper Input Validation vulnerability in Apache Traffic Server.
| This issue affects Apache Traffic Server: from 9.2.0 through 9.2.14,
| from 10.1.0 through 10.1.3.  Users are recommended to upgrade to
| version 9.2.15 or 10.1.4, which fixes the issue.


CVE-2026-33930[3]:
| Apache Traffic Server copies the client Host header into a fixed-
| size stack buffer without a bound during redirect handling, so an
| over-long Host header overflows the stack when redirect following is
| enabled.  This issue affects Apache Traffic Server: from 8.0.0
| through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through
| 10.1.3.  Users are recommended to upgrade to version 9.2.15 or
| 10.1.4, which fix the issue.


CVE-2026-41920[4]:
| Improper Access Control vulnerability in Apache Traffic Server.
| This issue affects Apache Traffic Server: from 9.0.0 through 9.1.14,
| from 10.0.0 through 10.1.3.  Users are recommended to upgrade to
| version 9.1.15 or 10.1.4, which fixes the issue.


CVE-2026-57834[5]:
| Apache Traffic Server allows request smuggling if chunked messages
| are malformed.  This issue affects Apache Traffic Server: from 8.0.0
| through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through
| 10.1.3.  Users are recommended to upgrade to version 9.2.15 or
| 10.1.4, which fix the issue.


CVE-2026-58150[6]:
| Apache Traffic Server does not reject Transfer-Encoding in HTTP/2
| requests, allowing downgrade request smuggling.  This issue affects
| Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through
| 9.2.14, from 10.0.0 through 10.1.3.  Users are recommended to
| upgrade to version 9.2.15 or 10.1.4, which fix the issue.


CVE-2026-58151[7]:
| Apache Traffic Server can be crashed or driven to resource
| exhaustion by abusive HTTP/2 framing and flow-control.  This issue
| affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0
| through 9.2.14, from 10.0.0 through 10.1.3.  Users are recommended
| to upgrade to version 9.2.15 or 10.1.4, which fix the issue.


CVE-2026-58152[8]:
| Apache Traffic Server mishandles integers while decoding HPACK/XPACK
| headers, corrupting memory.  This issue affects Apache Traffic
| Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from
| 10.0.0 through 10.1.3.  Users are recommended to upgrade to version
| 9.2.15 or 10.1.4, which fix the issue.


CVE-2026-58153[9]:
| Apache Traffic Server forwards HTTP/2 origin trailers to HTTP/1
| clients without proper chunked framing when converting HTTP/2 to
| HTTP/1.  This issue affects Apache Traffic Server: from 10.0.0
| through 10.1.3.  Users are recommended to upgrade to version 9.2.15
| or 10.1.4, which fix the issue.


CVE-2026-58154[10]:
| Apache Traffic Server can write out of bounds or overflow integers
| while parsing MIME and HTTP headers.  This issue affects Apache
| Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14,
| from 10.0.0 through 10.1.3.  Users are recommended to upgrade to
| version 9.2.15 or 10.1.4, which fix the issue.


CVE-2026-58155[11]:
| Apache Traffic Server truncates over-long header names, allowing
| header aliasing, request smuggling, and policy bypass.  This issue
| affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0
| through 9.2.14, from 10.0.0 through 10.1.3.  Users are recommended
| to upgrade to version 9.2.15 or 10.1.4, which fix the issue.


CVE-2026-58156[12]:
| Apache Traffic Server mis-parses ports in URLs and userinfo,
| allowing port-based access-control bypass.  This issue affects
| Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through
| 9.2.14, from 10.0.0 through 10.1.3.  Users are recommended to
| upgrade to version 9.2.15 or 10.1.4, which fix the issue.


CVE-2026-58157[13]:
| Apache Traffic Server can reuse server sessions and tunnels
| improperly, exposing data across client connections.  This issue
| affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0
| through 9.2.14, from 10.0.0 through 10.1.3.  Users are recommended
| to upgrade to version 9.2.15 or 10.1.4, which fix the issue.


CVE-2026-58158[14]:
| Apache Traffic Server mishandles PROXY protocol input, truncating
| ports and overflowing the stack.  This issue affects Apache Traffic
| Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from
| 10.0.0 through 10.1.3.  Users are recommended to upgrade to version
| 9.2.15 or 10.1.4, which fix the issue.


CVE-2026-58159[15]:
| Apache Traffic Server can bypass IP access controls on UDS listeners
| and through ACL matching errors.  This issue affects Apache Traffic
| Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from
| 10.0.0 through 10.1.3.  Users are recommended to upgrade to version
| 9.2.15 or 10.1.4, which fix the issue.


CVE-2026-58160[16]:
| Apache Traffic Server reads out of bounds while parsing DNS answers.
| This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9,
| from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3.  Users are
| recommended to upgrade to version 9.2.15 or 10.1.4, which fix the
| issue.


CVE-2026-58161[17]:
| Apache Traffic Server can crash from null dereferences and dangling
| references in TLS and SNI handling.  This issue affects Apache
| Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14,
| from 10.0.0 through 10.1.3.  Users are recommended to upgrade to
| version 9.2.15 or 10.1.4, which fix the issue.


CVE-2026-58162[18]:
| The Apache Traffic Server certifier plugin generates certificates
| based on attacker-controlled client SNI.  This issue affects Apache
| Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14,
| from 10.0.0 through 10.1.3.  Users are recommended to upgrade to
| version 9.2.15 or 10.1.4, which fix the issue.


CVE-2026-58163[19]:
| Apache Traffic Server mishandles on-disk cache fields and object
| lifetimes, corrupting state or crashing.  This issue affects Apache
| Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14,
| from 10.0.0 through 10.1.3.  Users are recommended to upgrade to
| version 9.2.15 or 10.1.4, which fix the issue.


CVE-2026-58164[20]:
| Apache Traffic Server has use-after-free and time-of-check/time-of-
| use errors in remap configuration handling.  This issue affects
| Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through
| 9.2.14, from 10.0.0 through 10.1.3.  Users are recommended to
| upgrade to version 9.2.15 or 10.1.4, which fix the issue.


CVE-2026-58175[21]:
| Apache Traffic Server leaks memory when handling HostDB SRV records.
| This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9,
| from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3.  Users are
| recommended to upgrade to version 9.2.15 or 10.1.4, which fix the
| issue.


CVE-2026-58177[22]:
| The Apache Traffic Server Cripts framework has out-of-bounds writes,
| path traversal, and use-after-free errors.  This issue affects
| Apache Traffic Server: from 10.0.0 through 10.1.3.  Users are
| recommended to upgrade to version 10.1.4, which fix the issue.


CVE-2026-58178[23]:
| The Apache Traffic Server ESI plugin can recurse without bound and
| fetch attacker-controlled URLs.  This issue affects Apache Traffic
| Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from
| 10.0.0 through 10.1.3.  Users are recommended to upgrade to version
| 9.2.15 or 10.1.4, which fix the issue.


CVE-2026-58179[24]:
| The Apache Traffic Server regex_remap plugin overflows the stack and
| integers from substitution input.  This issue affects Apache Traffic
| Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from
| 10.0.0 through 10.1.3.  Users are recommended to upgrade to version
| 9.2.15 or 10.1.4, which fix the issue.


CVE-2026-58180[25]:
| The Apache Traffic Server txn_box plugin overflows the stack from
| attacker-controlled input.  This issue affects Apache Traffic
| Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from
| 10.0.0 through 10.1.3.  Users are recommended to upgrade to version
| 9.2.15 or 10.1.4, which fix the issue.


CVE-2026-58181[26]:
| The Apache Traffic Server uri_signing and url_sig plugins can
| exhaust the stack or crash on attacker input.  This issue affects
| Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through
| 9.2.14, from 10.0.0 through 10.1.3.  Users are recommended to
| upgrade to version 9.2.15 or 10.1.4, which fix the issue.


CVE-2026-58182[27]:
| The Apache Traffic Server ts_lua plugin mishandles initialization,
| transform context, and per-instance state.  This issue affects
| Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through
| 9.2.14, from 10.0.0 through 10.1.3.  Users are recommended to
| upgrade to version 9.2.15 or 10.1.4, which fix the issue.


CVE-2026-58183[28]:
| The Apache Traffic Server prefetch plugin can crash when processing
| attacker-influenced input.  This issue affects Apache Traffic
| Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from
| 10.0.0 through 10.1.3.  Users are recommended to upgrade to version
| 9.2.15 or 10.1.4, which fix the issue.


CVE-2026-58184[29]:
| The Apache Traffic Server header_rewrite plugin can crash or corrupt
| memory during cookie operations and CIDR condition matching.  This
| issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from
| 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3.  Users are
| recommended to upgrade to version 9.2.15 or 10.1.4, which fix the
| issue.


CVE-2026-58185[30]:
| The Apache Traffic Server intercept plugin has a use-after-free.
| This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9,
| from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3.  Users are
| recommended to upgrade to version 9.2.15 or 10.1.4, which fix the
| issue.


CVE-2026-58186[31]:
| The Apache Traffic Server webp_transform plugin can decode unsafely
| and serve mislabeled, cacheable responses.  This issue affects
| Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through
| 9.2.14, from 10.0.0 through 10.1.3.  Users are recommended to
| upgrade to version 9.2.15 or 10.1.4, which fix the issue.


CVE-2026-58187[32]:
| The Apache Traffic Server multiplexer plugin overruns its chunk-
| decode buffer on upstream input, enabling denial of service.  This
| issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from
| 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3.  Users are
| recommended to upgrade to version 9.2.15 or 10.1.4, which fix the
| issue.


CVE-2026-58188[33]:
| Several Apache Traffic Server experimental plugins have memory-
| safety and limit-bypass errors.  This issue affects Apache Traffic
| Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from
| 10.0.0 through 10.1.3.  Users are recommended to upgrade to version
| 9.2.15 or 10.1.4, which fix the issue.


CVE-2026-58189[34]:
| Apache Traffic Server allows redirect-limit bypass when plugins
| reset the retry counter, enabling SSRF amplification.  This issue
| affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0
| through 9.2.14, from 10.0.0 through 10.1.3.  Users are recommended
| to upgrade to version 9.2.15 or 10.1.4, which fix the issue.


CVE-2026-65100[35]:
| Apache Traffic Server updates the HTTP/2 HPACK dynamic table before
| confirming the header block encoded successfully, so an encode
| failure leaves the encoder out of sync with the peer decoder and
| corrupts subsequent header blocks on the connection.  This issue
| affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0
| through 9.2.14, from 10.0.0 through 10.1.3.  Users are recommended
| to upgrade to version 9.2.15 or 10.1.4, which fix the issue.


CVE-2026-65324[36]:
| Apache Traffic Server drops the per-stream buffer cap when
| dechunking HTTP/2 or HTTP/3 responses, letting a slow client exhaust
| server memory.  This issue affects Apache Traffic Server: from 8.0.0
| through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through
| 10.1.3.  Users are recommended to upgrade to version 9.2.15 or
| 10.1.4, which fix the issue.


CVE-2026-65325[37]:
| Apache Traffic Server reuses multiplexed HTTP/2 origin connections
| without verifying the server certificate covers the new request
| hostname.  This issue affects Apache Traffic Server: from 9.0.0
| through 9.2.14, from 10.0.0 through 10.1.3.  Users are recommended
| to upgrade to version 9.2.15 or 10.1.4, which fix the issue.


If you fix the vulnerabilities please also make sure to include the
CVE (Common Vulnerabilities & Exposures) ids in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-22068
https://www.cve.org/CVERecord?id=CVE-2026-22068
[1] https://security-tracker.debian.org/tracker/CVE-2026-24033
https://www.cve.org/CVERecord?id=CVE-2026-24033
[2] https://security-tracker.debian.org/tracker/CVE-2026-33267
https://www.cve.org/CVERecord?id=CVE-2026-33267
[3] https://security-tracker.debian.org/tracker/CVE-2026-33930
https://www.cve.org/CVERecord?id=CVE-2026-33930
[4] https://security-tracker.debian.org/tracker/CVE-2026-41920
https://www.cve.org/CVERecord?id=CVE-2026-41920
[5] https://security-tracker.debian.org/tracker/CVE-2026-57834
https://www.cve.org/CVERecord?id=CVE-2026-57834
[6] https://security-tracker.debian.org/tracker/CVE-2026-58150
https://www.cve.org/CVERecord?id=CVE-2026-58150
[7] https://security-tracker.debian.org/tracker/CVE-2026-58151
https://www.cve.org/CVERecord?id=CVE-2026-58151
[8] https://security-tracker.debian.org/tracker/CVE-2026-58152
https://www.cve.org/CVERecord?id=CVE-2026-58152
[9] https://security-tracker.debian.org/tracker/CVE-2026-58153
https://www.cve.org/CVERecord?id=CVE-2026-58153
[10] https://security-tracker.debian.org/tracker/CVE-2026-58154
https://www.cve.org/CVERecord?id=CVE-2026-58154
[11] https://security-tracker.debian.org/tracker/CVE-2026-58155
https://www.cve.org/CVERecord?id=CVE-2026-58155
[12] https://security-tracker.debian.org/tracker/CVE-2026-58156
https://www.cve.org/CVERecord?id=CVE-2026-58156
[13] https://security-tracker.debian.org/tracker/CVE-2026-58157
https://www.cve.org/CVERecord?id=CVE-2026-58157
[14] https://security-tracker.debian.org/tracker/CVE-2026-58158
https://www.cve.org/CVERecord?id=CVE-2026-58158
[15] https://security-tracker.debian.org/tracker/CVE-2026-58159
https://www.cve.org/CVERecord?id=CVE-2026-58159
[16] https://security-tracker.debian.org/tracker/CVE-2026-58160
https://www.cve.org/CVERecord?id=CVE-2026-58160
[17] https://security-tracker.debian.org/tracker/CVE-2026-58161
https://www.cve.org/CVERecord?id=CVE-2026-58161
[18] https://security-tracker.debian.org/tracker/CVE-2026-58162
https://www.cve.org/CVERecord?id=CVE-2026-58162
[19] https://security-tracker.debian.org/tracker/CVE-2026-58163
https://www.cve.org/CVERecord?id=CVE-2026-58163
[20] https://security-tracker.debian.org/tracker/CVE-2026-58164
https://www.cve.org/CVERecord?id=CVE-2026-58164
[21] https://security-tracker.debian.org/tracker/CVE-2026-58175
https://www.cve.org/CVERecord?id=CVE-2026-58175
[22] https://security-tracker.debian.org/tracker/CVE-2026-58177
https://www.cve.org/CVERecord?id=CVE-2026-58177
[23] https://security-tracker.debian.org/tracker/CVE-2026-58178
https://www.cve.org/CVERecord?id=CVE-2026-58178
[24] https://security-tracker.debian.org/tracker/CVE-2026-58179
https://www.cve.org/CVERecord?id=CVE-2026-58179
[25] https://security-tracker.debian.org/tracker/CVE-2026-58180
https://www.cve.org/CVERecord?id=CVE-2026-58180
[26] https://security-tracker.debian.org/tracker/CVE-2026-58181
https://www.cve.org/CVERecord?id=CVE-2026-58181
[27] https://security-tracker.debian.org/tracker/CVE-2026-58182
https://www.cve.org/CVERecord?id=CVE-2026-58182
[28] https://security-tracker.debian.org/tracker/CVE-2026-58183
https://www.cve.org/CVERecord?id=CVE-2026-58183
[29] https://security-tracker.debian.org/tracker/CVE-2026-58184
https://www.cve.org/CVERecord?id=CVE-2026-58184
[30] https://security-tracker.debian.org/tracker/CVE-2026-58185
https://www.cve.org/CVERecord?id=CVE-2026-58185
[31] https://security-tracker.debian.org/tracker/CVE-2026-58186
https://www.cve.org/CVERecord?id=CVE-2026-58186
[32] https://security-tracker.debian.org/tracker/CVE-2026-58187
https://www.cve.org/CVERecord?id=CVE-2026-58187
[33] https://security-tracker.debian.org/tracker/CVE-2026-58188
https://www.cve.org/CVERecord?id=CVE-2026-58188
[34] https://security-tracker.debian.org/tracker/CVE-2026-58189
https://www.cve.org/CVERecord?id=CVE-2026-58189
[35] https://security-tracker.debian.org/tracker/CVE-2026-65100
https://www.cve.org/CVERecord?id=CVE-2026-65100
[36] https://security-tracker.debian.org/tracker/CVE-2026-65324
https://www.cve.org/CVERecord?id=CVE-2026-65324
[37] https://security-tracker.debian.org/tracker/CVE-2026-65325
https://www.cve.org/CVERecord?id=CVE-2026-65325

Regards,
Salvatore

#1143062#10
Date:
2026-09-21 13:43:07 UTC
From:
To:
Dear submitter,

as the package trafficserver has just been removed from the Debian archive
unstable we hereby close the associated bug reports.  We are sorry
that we couldn't deal with your issue properly.

For details on the removal, please see https://bugs.debian.org/1116680

The version of this package that was in Debian prior to this removal
can still be found using https://snapshot.debian.org/.

Please note that the changes have been done on the master archive and
will not propagate to any mirrors until the next dinstall run at the
earliest.

This message was generated automatically; if you believe that there is
a problem with it please contact the archive administrators by mailing
ftpmaster@ftp-master.debian.org.

Debian distribution maintenance software
pp.
Thorsten Alteholz (the ftpmaster behind the curtain)