CVE-2026-58162Generación de certificados arbitrarios en Apache Traffic Server
The Apache Traffic Server certifier plugin generates certificates based on attacker-controlled client SNI. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.
Ver en NVDAnálisis
El plugin certifier de Apache Traffic Server permite la generacion de certificados digitales basados en el SNI controlado por un atacante. Este fallo de validacion permite comprometer la integridad de las comunicaciones TLS y suplantar identidades en la infraestructura de red. Se recomienda actualizar inmediatamente a las versiones 9.2.15 o 10.1.4.
Roles relevantes
Severidad
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:H/A:HCWE-295EPSS
Sin puntaje EPSS aún (CVE muy reciente).
Descripción técnica
The Apache Traffic Server certifier plugin generates certificates based on attacker-controlled client SNI. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.