CVE-2026-57834Request Smuggling en Apache Traffic Server
Apache Traffic Server allows request smuggling if chunked messages are malformed. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.
Ver en NVDAnálisis
Apache Traffic Server permite ataques de Request Smuggling debido al manejo incorrecto de mensajes con codificación chunked. Un atacante puede manipular peticiones para evadir controles de seguridad o envenenar el caché del servidor, afectando a otros usuarios. Se recomienda actualizar a las versiones 9.2.15 o 10.1.4.
Roles relevantes
Severidad
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:LCWE-444EPSS
Sin puntaje EPSS aún (CVE muy reciente).
Descripción técnica
Apache Traffic Server allows request smuggling if chunked messages are malformed. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.