CVE-2026-58155Request Smuggling crítico en Apache Traffic Server
Apache Traffic Server truncates over-long header names, allowing header aliasing, request smuggling, and policy bypass. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.
Ver en NVDAnálisis
Apache Traffic Server (ATS) is vulnerable to critical request smuggling and policy bypass. Attackers can exploit improper header name truncation to bypass security filters or alias headers, potentially compromising the integrity of backend communications.
Severidad
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:H/A:NCWE-444EPSS
Sin puntaje EPSS aún (CVE muy reciente).
Descripción técnica
Apache Traffic Server truncates over-long header names, allowing header aliasing, request smuggling, and policy bypass. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.