Skip to content
CVSS 10.0CVSS 10.0 · CRITICAL

CVE-2026-58150Request Smuggling en Apache Traffic Server

Apache Traffic Server does not reject Transfer-Encoding in HTTP/2 requests, allowing downgrade request smuggling. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.

Ver en NVD

Análisis

Apache Traffic Server es vulnerable a Request Smuggling debido a un manejo incorrecto de la cabecera Transfer-Encoding en conexiones HTTP/2. Un atacante puede explotar este fallo para eludir firewalls de aplicaciones web, envenenar la caché del servidor o interceptar sesiones de usuarios legítimos. Es imperativo actualizar a las versiones 9.2.15 o 10.1.4 para mitigar este riesgo crítico con severidad máxima.

Roles relevantes

BackendCyberSecurityCloudLinuxDockerKubernetes

Severidad

Puntaje: 10.0(CRITICAL)
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N
AV: NETWORK
AC: LOW
PR: NONE
UI: NONE
S: CHANGED
C: HIGH
I: HIGH
A: NONE
Tipo de falla (CWE): CWE-444

EPSS

Sin puntaje EPSS aún (CVE muy reciente).

Descripción técnica

Apache Traffic Server does not reject Transfer-Encoding in HTTP/2 requests, allowing downgrade request smuggling. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.

Publicada: 29/7/2026, 8:16:31
Última modificación: 29/7/2026, 8:16:31

Referencias

InicioEventosBlogRecursosCursosEquipo