← Browse

CVE-2026-58154

Medium

Elevated severity or exploit probability.

CVSS base
8.9 HIGH
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:H/A:H
EPSS — probability of exploitation (30 days)
0.4%
33.9th percentile
CISA KEV
Not listed
Weakness / dates
CWE-787
Published 2026-07-29 · modified 2026-08-03

CVSS breakdown

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:H/A:H

Attack VectorNNetwork
Attack ComplexityHHigh
Privileges RequiredNNone
User InteractionNNone
ScopeCChanged
ConfidentialityLLow
IntegrityHHigh
AvailabilityHHigh

Timeline

Description

Apache Traffic Server can write out of bounds or overflow integers while parsing MIME and HTTP headers. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.

Affected

apache

References

Official: NVD · CVE.org