#1143062 trafficserver: CVE-2026-22068 CVE-2026-24033 CVE-2026-33267 CVE-2026-33930 CVE-2026-41920 CVE-2026-57834 CVE-2026-58150 CVE-2026-58151 CVE-2026-58152 CVE-2026-58153 CVE-2026-58154 CVE-2026-58155 CVE-2026-58156 CVE-2026-58157 CVE-2026-58158 CVE-2026-58159 CVE-2026-58160 CVE-2026-58161 CVE-2026-58162 CVE-2026-58163 CVE-2026-58164 CVE-2026-58175 CVE-2026-58177 CVE-2026-58178 CVE-2026-58179 CVE-2026-58180 CVE-2026-58181 CVE-2026-58182 CVE-2026-58183 CVE-2026-58184 CVE-2026-58185 CVE-2026-58186 CVE-2026-58187 CVE-2026-58188 CVE-2026-58189 CVE-2026-65100 CVE-2026-65324 CVE-2026-65325

Package:
src:trafficserver
Source:
src:trafficserver
Submitter:
Salvatore Bonaccorso
Date:
2026-07-30 04:59:02 UTC
Severity:
normal
Tags:
#1143062#5
Date:
2026-07-30 04:57:49 UTC
From:
To:
Hi,

The following vulnerabilities were published for trafficserver.

CVE-2026-22068[0]:
| Regular Expression without Anchors vulnerability in Apache Traffic
| Server.  This issue affects Apache Traffic Server: from 10.0.X
| through 10.1.3, from 9.0.X through 9.2.14.  Users are recommended to
| upgrade to version 9.2.15 or 10.1.4, which fixes the issue.


CVE-2026-24033[1]:
| Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response
| Smuggling') vulnerability in Apache Traffic Server.  This issue
| affects Apache Traffic Server: from 10.0.0 through 10.1.3, from
| 9.0.0 through 9.2.14.  Users are recommended to upgrade to version
| 9.2.15 or 10.1.4, which fixes the issue.


CVE-2026-33267[2]:
| Improper Input Validation vulnerability in Apache Traffic Server.
| This issue affects Apache Traffic Server: from 9.2.0 through 9.2.14,
| from 10.1.0 through 10.1.3.  Users are recommended to upgrade to
| version 9.2.15 or 10.1.4, which fixes the issue.


CVE-2026-33930[3]:
| Apache Traffic Server copies the client Host header into a fixed-
| size stack buffer without a bound during redirect handling, so an
| over-long Host header overflows the stack when redirect following is
| enabled.  This issue affects Apache Traffic Server: from 8.0.0
| through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through
| 10.1.3.  Users are recommended to upgrade to version 9.2.15 or
| 10.1.4, which fix the issue.


CVE-2026-41920[4]:
| Improper Access Control vulnerability in Apache Traffic Server.
| This issue affects Apache Traffic Server: from 9.0.0 through 9.1.14,
| from 10.0.0 through 10.1.3.  Users are recommended to upgrade to
| version 9.1.15 or 10.1.4, which fixes the issue.


CVE-2026-57834[5]:
| Apache Traffic Server allows request smuggling if chunked messages
| are malformed.  This issue affects Apache Traffic Server: from 8.0.0
| through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through
| 10.1.3.  Users are recommended to upgrade to version 9.2.15 or
| 10.1.4, which fix the issue.


CVE-2026-58150[6]:
| Apache Traffic Server does not reject Transfer-Encoding in HTTP/2
| requests, allowing downgrade request smuggling.  This issue affects
| Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through
| 9.2.14, from 10.0.0 through 10.1.3.  Users are recommended to
| upgrade to version 9.2.15 or 10.1.4, which fix the issue.


CVE-2026-58151[7]:
| Apache Traffic Server can be crashed or driven to resource
| exhaustion by abusive HTTP/2 framing and flow-control.  This issue
| affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0
| through 9.2.14, from 10.0.0 through 10.1.3.  Users are recommended
| to upgrade to version 9.2.15 or 10.1.4, which fix the issue.


CVE-2026-58152[8]:
| Apache Traffic Server mishandles integers while decoding HPACK/XPACK
| headers, corrupting memory.  This issue affects Apache Traffic
| Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from
| 10.0.0 through 10.1.3.  Users are recommended to upgrade to version
| 9.2.15 or 10.1.4, which fix the issue.


CVE-2026-58153[9]:
| Apache Traffic Server forwards HTTP/2 origin trailers to HTTP/1
| clients without proper chunked framing when converting HTTP/2 to
| HTTP/1.  This issue affects Apache Traffic Server: from 10.0.0
| through 10.1.3.  Users are recommended to upgrade to version 9.2.15
| or 10.1.4, which fix the issue.


CVE-2026-58154[10]:
| Apache Traffic Server can write out of bounds or overflow integers
| while parsing MIME and HTTP headers.  This issue affects Apache
| Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14,
| from 10.0.0 through 10.1.3.  Users are recommended to upgrade to
| version 9.2.15 or 10.1.4, which fix the issue.


CVE-2026-58155[11]:
| Apache Traffic Server truncates over-long header names, allowing
| header aliasing, request smuggling, and policy bypass.  This issue
| affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0
| through 9.2.14, from 10.0.0 through 10.1.3.  Users are recommended
| to upgrade to version 9.2.15 or 10.1.4, which fix the issue.


CVE-2026-58156[12]:
| Apache Traffic Server mis-parses ports in URLs and userinfo,
| allowing port-based access-control bypass.  This issue affects
| Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through
| 9.2.14, from 10.0.0 through 10.1.3.  Users are recommended to
| upgrade to version 9.2.15 or 10.1.4, which fix the issue.


CVE-2026-58157[13]:
| Apache Traffic Server can reuse server sessions and tunnels
| improperly, exposing data across client connections.  This issue
| affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0
| through 9.2.14, from 10.0.0 through 10.1.3.  Users are recommended
| to upgrade to version 9.2.15 or 10.1.4, which fix the issue.


CVE-2026-58158[14]:
| Apache Traffic Server mishandles PROXY protocol input, truncating
| ports and overflowing the stack.  This issue affects Apache Traffic
| Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from
| 10.0.0 through 10.1.3.  Users are recommended to upgrade to version
| 9.2.15 or 10.1.4, which fix the issue.


CVE-2026-58159[15]:
| Apache Traffic Server can bypass IP access controls on UDS listeners
| and through ACL matching errors.  This issue affects Apache Traffic
| Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from
| 10.0.0 through 10.1.3.  Users are recommended to upgrade to version
| 9.2.15 or 10.1.4, which fix the issue.


CVE-2026-58160[16]:
| Apache Traffic Server reads out of bounds while parsing DNS answers.
| This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9,
| from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3.  Users are
| recommended to upgrade to version 9.2.15 or 10.1.4, which fix the
| issue.


CVE-2026-58161[17]:
| Apache Traffic Server can crash from null dereferences and dangling
| references in TLS and SNI handling.  This issue affects Apache
| Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14,
| from 10.0.0 through 10.1.3.  Users are recommended to upgrade to
| version 9.2.15 or 10.1.4, which fix the issue.


CVE-2026-58162[18]:
| The Apache Traffic Server certifier plugin generates certificates
| based on attacker-controlled client SNI.  This issue affects Apache
| Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14,
| from 10.0.0 through 10.1.3.  Users are recommended to upgrade to
| version 9.2.15 or 10.1.4, which fix the issue.


CVE-2026-58163[19]:
| Apache Traffic Server mishandles on-disk cache fields and object
| lifetimes, corrupting state or crashing.  This issue affects Apache
| Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14,
| from 10.0.0 through 10.1.3.  Users are recommended to upgrade to
| version 9.2.15 or 10.1.4, which fix the issue.


CVE-2026-58164[20]:
| Apache Traffic Server has use-after-free and time-of-check/time-of-
| use errors in remap configuration handling.  This issue affects
| Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through
| 9.2.14, from 10.0.0 through 10.1.3.  Users are recommended to
| upgrade to version 9.2.15 or 10.1.4, which fix the issue.


CVE-2026-58175[21]:
| Apache Traffic Server leaks memory when handling HostDB SRV records.
| This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9,
| from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3.  Users are
| recommended to upgrade to version 9.2.15 or 10.1.4, which fix the
| issue.


CVE-2026-58177[22]:
| The Apache Traffic Server Cripts framework has out-of-bounds writes,
| path traversal, and use-after-free errors.  This issue affects
| Apache Traffic Server: from 10.0.0 through 10.1.3.  Users are
| recommended to upgrade to version 10.1.4, which fix the issue.


CVE-2026-58178[23]:
| The Apache Traffic Server ESI plugin can recurse without bound and
| fetch attacker-controlled URLs.  This issue affects Apache Traffic
| Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from
| 10.0.0 through 10.1.3.  Users are recommended to upgrade to version
| 9.2.15 or 10.1.4, which fix the issue.


CVE-2026-58179[24]:
| The Apache Traffic Server regex_remap plugin overflows the stack and
| integers from substitution input.  This issue affects Apache Traffic
| Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from
| 10.0.0 through 10.1.3.  Users are recommended to upgrade to version
| 9.2.15 or 10.1.4, which fix the issue.


CVE-2026-58180[25]:
| The Apache Traffic Server txn_box plugin overflows the stack from
| attacker-controlled input.  This issue affects Apache Traffic
| Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from
| 10.0.0 through 10.1.3.  Users are recommended to upgrade to version
| 9.2.15 or 10.1.4, which fix the issue.


CVE-2026-58181[26]:
| The Apache Traffic Server uri_signing and url_sig plugins can
| exhaust the stack or crash on attacker input.  This issue affects
| Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through
| 9.2.14, from 10.0.0 through 10.1.3.  Users are recommended to
| upgrade to version 9.2.15 or 10.1.4, which fix the issue.


CVE-2026-58182[27]:
| The Apache Traffic Server ts_lua plugin mishandles initialization,
| transform context, and per-instance state.  This issue affects
| Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through
| 9.2.14, from 10.0.0 through 10.1.3.  Users are recommended to
| upgrade to version 9.2.15 or 10.1.4, which fix the issue.


CVE-2026-58183[28]:
| The Apache Traffic Server prefetch plugin can crash when processing
| attacker-influenced input.  This issue affects Apache Traffic
| Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from
| 10.0.0 through 10.1.3.  Users are recommended to upgrade to version
| 9.2.15 or 10.1.4, which fix the issue.


CVE-2026-58184[29]:
| The Apache Traffic Server header_rewrite plugin can crash or corrupt
| memory during cookie operations and CIDR condition matching.  This
| issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from
| 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3.  Users are
| recommended to upgrade to version 9.2.15 or 10.1.4, which fix the
| issue.


CVE-2026-58185[30]:
| The Apache Traffic Server intercept plugin has a use-after-free.
| This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9,
| from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3.  Users are
| recommended to upgrade to version 9.2.15 or 10.1.4, which fix the
| issue.


CVE-2026-58186[31]:
| The Apache Traffic Server webp_transform plugin can decode unsafely
| and serve mislabeled, cacheable responses.  This issue affects
| Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through
| 9.2.14, from 10.0.0 through 10.1.3.  Users are recommended to
| upgrade to version 9.2.15 or 10.1.4, which fix the issue.


CVE-2026-58187[32]:
| The Apache Traffic Server multiplexer plugin overruns its chunk-
| decode buffer on upstream input, enabling denial of service.  This
| issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from
| 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3.  Users are
| recommended to upgrade to version 9.2.15 or 10.1.4, which fix the
| issue.


CVE-2026-58188[33]:
| Several Apache Traffic Server experimental plugins have memory-
| safety and limit-bypass errors.  This issue affects Apache Traffic
| Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from
| 10.0.0 through 10.1.3.  Users are recommended to upgrade to version
| 9.2.15 or 10.1.4, which fix the issue.


CVE-2026-58189[34]:
| Apache Traffic Server allows redirect-limit bypass when plugins
| reset the retry counter, enabling SSRF amplification.  This issue
| affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0
| through 9.2.14, from 10.0.0 through 10.1.3.  Users are recommended
| to upgrade to version 9.2.15 or 10.1.4, which fix the issue.


CVE-2026-65100[35]:
| Apache Traffic Server updates the HTTP/2 HPACK dynamic table before
| confirming the header block encoded successfully, so an encode
| failure leaves the encoder out of sync with the peer decoder and
| corrupts subsequent header blocks on the connection.  This issue
| affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0
| through 9.2.14, from 10.0.0 through 10.1.3.  Users are recommended
| to upgrade to version 9.2.15 or 10.1.4, which fix the issue.


CVE-2026-65324[36]:
| Apache Traffic Server drops the per-stream buffer cap when
| dechunking HTTP/2 or HTTP/3 responses, letting a slow client exhaust
| server memory.  This issue affects Apache Traffic Server: from 8.0.0
| through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through
| 10.1.3.  Users are recommended to upgrade to version 9.2.15 or
| 10.1.4, which fix the issue.


CVE-2026-65325[37]:
| Apache Traffic Server reuses multiplexed HTTP/2 origin connections
| without verifying the server certificate covers the new request
| hostname.  This issue affects Apache Traffic Server: from 9.0.0
| through 9.2.14, from 10.0.0 through 10.1.3.  Users are recommended
| to upgrade to version 9.2.15 or 10.1.4, which fix the issue.


If you fix the vulnerabilities please also make sure to include the
CVE (Common Vulnerabilities & Exposures) ids in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-22068
https://www.cve.org/CVERecord?id=CVE-2026-22068
[1] https://security-tracker.debian.org/tracker/CVE-2026-24033
https://www.cve.org/CVERecord?id=CVE-2026-24033
[2] https://security-tracker.debian.org/tracker/CVE-2026-33267
https://www.cve.org/CVERecord?id=CVE-2026-33267
[3] https://security-tracker.debian.org/tracker/CVE-2026-33930
https://www.cve.org/CVERecord?id=CVE-2026-33930
[4] https://security-tracker.debian.org/tracker/CVE-2026-41920
https://www.cve.org/CVERecord?id=CVE-2026-41920
[5] https://security-tracker.debian.org/tracker/CVE-2026-57834
https://www.cve.org/CVERecord?id=CVE-2026-57834
[6] https://security-tracker.debian.org/tracker/CVE-2026-58150
https://www.cve.org/CVERecord?id=CVE-2026-58150
[7] https://security-tracker.debian.org/tracker/CVE-2026-58151
https://www.cve.org/CVERecord?id=CVE-2026-58151
[8] https://security-tracker.debian.org/tracker/CVE-2026-58152
https://www.cve.org/CVERecord?id=CVE-2026-58152
[9] https://security-tracker.debian.org/tracker/CVE-2026-58153
https://www.cve.org/CVERecord?id=CVE-2026-58153
[10] https://security-tracker.debian.org/tracker/CVE-2026-58154
https://www.cve.org/CVERecord?id=CVE-2026-58154
[11] https://security-tracker.debian.org/tracker/CVE-2026-58155
https://www.cve.org/CVERecord?id=CVE-2026-58155
[12] https://security-tracker.debian.org/tracker/CVE-2026-58156
https://www.cve.org/CVERecord?id=CVE-2026-58156
[13] https://security-tracker.debian.org/tracker/CVE-2026-58157
https://www.cve.org/CVERecord?id=CVE-2026-58157
[14] https://security-tracker.debian.org/tracker/CVE-2026-58158
https://www.cve.org/CVERecord?id=CVE-2026-58158
[15] https://security-tracker.debian.org/tracker/CVE-2026-58159
https://www.cve.org/CVERecord?id=CVE-2026-58159
[16] https://security-tracker.debian.org/tracker/CVE-2026-58160
https://www.cve.org/CVERecord?id=CVE-2026-58160
[17] https://security-tracker.debian.org/tracker/CVE-2026-58161
https://www.cve.org/CVERecord?id=CVE-2026-58161
[18] https://security-tracker.debian.org/tracker/CVE-2026-58162
https://www.cve.org/CVERecord?id=CVE-2026-58162
[19] https://security-tracker.debian.org/tracker/CVE-2026-58163
https://www.cve.org/CVERecord?id=CVE-2026-58163
[20] https://security-tracker.debian.org/tracker/CVE-2026-58164
https://www.cve.org/CVERecord?id=CVE-2026-58164
[21] https://security-tracker.debian.org/tracker/CVE-2026-58175
https://www.cve.org/CVERecord?id=CVE-2026-58175
[22] https://security-tracker.debian.org/tracker/CVE-2026-58177
https://www.cve.org/CVERecord?id=CVE-2026-58177
[23] https://security-tracker.debian.org/tracker/CVE-2026-58178
https://www.cve.org/CVERecord?id=CVE-2026-58178
[24] https://security-tracker.debian.org/tracker/CVE-2026-58179
https://www.cve.org/CVERecord?id=CVE-2026-58179
[25] https://security-tracker.debian.org/tracker/CVE-2026-58180
https://www.cve.org/CVERecord?id=CVE-2026-58180
[26] https://security-tracker.debian.org/tracker/CVE-2026-58181
https://www.cve.org/CVERecord?id=CVE-2026-58181
[27] https://security-tracker.debian.org/tracker/CVE-2026-58182
https://www.cve.org/CVERecord?id=CVE-2026-58182
[28] https://security-tracker.debian.org/tracker/CVE-2026-58183
https://www.cve.org/CVERecord?id=CVE-2026-58183
[29] https://security-tracker.debian.org/tracker/CVE-2026-58184
https://www.cve.org/CVERecord?id=CVE-2026-58184
[30] https://security-tracker.debian.org/tracker/CVE-2026-58185
https://www.cve.org/CVERecord?id=CVE-2026-58185
[31] https://security-tracker.debian.org/tracker/CVE-2026-58186
https://www.cve.org/CVERecord?id=CVE-2026-58186
[32] https://security-tracker.debian.org/tracker/CVE-2026-58187
https://www.cve.org/CVERecord?id=CVE-2026-58187
[33] https://security-tracker.debian.org/tracker/CVE-2026-58188
https://www.cve.org/CVERecord?id=CVE-2026-58188
[34] https://security-tracker.debian.org/tracker/CVE-2026-58189
https://www.cve.org/CVERecord?id=CVE-2026-58189
[35] https://security-tracker.debian.org/tracker/CVE-2026-65100
https://www.cve.org/CVERecord?id=CVE-2026-65100
[36] https://security-tracker.debian.org/tracker/CVE-2026-65324
https://www.cve.org/CVERecord?id=CVE-2026-65324
[37] https://security-tracker.debian.org/tracker/CVE-2026-65325
https://www.cve.org/CVERecord?id=CVE-2026-65325

Regards,
Salvatore