Skip to content
CVSS 9.3 · CRITICAL

CVE-2026-58155Critical Request Smuggling in Apache Traffic Server

Apache Traffic Server truncates over-long header names, allowing header aliasing, request smuggling, and policy bypass. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.

View on NVD

Analysis

Apache Traffic Server (ATS) is vulnerable to critical request smuggling and policy bypass. Attackers can exploit improper header name truncation to bypass security filters or alias headers, potentially compromising the integrity of backend communications.

Relevant roles

BackendCyberSecurityCloudKubernetesDockerLinux

Severity

Score: 9.3(CRITICAL)
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:H/A:N
AV: NETWORK
AC: LOW
PR: NONE
UI: NONE
S: CHANGED
C: LOW
I: HIGH
A: NONE
Weakness (CWE): CWE-444

EPSS

Probability of exploitation (next 30 days): 0.0026 (0.3%)
Percentile: 17.8%
EPSS: 2026-07-30

Technical description

Apache Traffic Server truncates over-long header names, allowing header aliasing, request smuggling, and policy bypass. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.

Published: 7/29/2026, 9:16:29 AM
Last modified: 7/30/2026, 2:54:03 PM

References

InicioEventosBlogRecursosCursosEquipo