CVE-2026-58150Request Smuggling en Apache Traffic Server
Apache Traffic Server does not reject Transfer-Encoding in HTTP/2 requests, allowing downgrade request smuggling. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.
Ver en NVDAnálisis
Apache Traffic Server es vulnerable a Request Smuggling debido a un manejo incorrecto de la cabecera Transfer-Encoding en conexiones HTTP/2. Un atacante puede explotar este fallo para eludir firewalls de aplicaciones web, envenenar la caché del servidor o interceptar sesiones de usuarios legítimos. Es imperativo actualizar a las versiones 9.2.15 o 10.1.4 para mitigar este riesgo crítico con severidad máxima.
Roles relevantes
Severidad
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:NCWE-444EPSS
Sin puntaje EPSS aún (CVE muy reciente).
Descripción técnica
Apache Traffic Server does not reject Transfer-Encoding in HTTP/2 requests, allowing downgrade request smuggling. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.