Skip to content
VulniPulse

Complete feed

Recently updated

Advisories the vendor has revised

Home overview

Android app · Google Play

Take your CVE monitoring with you.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

High8.3Apache

High [CVE-2026-58164] Apache Traffic Server has use-after-free and time-of-check/time-of-use errors in remap configuration handling

Apache Traffic Server has use-after-free and time-of-check/time-of-use errors in remap configuration handling. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.

CVE-2026-58164
Infra & Gateways
Jul 29, 2026
High8.3Apache

High [CVE-2026-58163] Apache Traffic Server mishandles on-disk cache fields and object lifetimes, corrupting state or crashing

Apache Traffic Server mishandles on-disk cache fields and object lifetimes, corrupting state or crashing. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.

CVE-2026-58163
Infra & Gateways
Jul 29, 2026
High8.4Apache

High [CVE-2026-58162] The Apache Traffic Server certifier plugin generates certificates based on attacker-controlled client SNI

The Apache Traffic Server certifier plugin generates certificates based on attacker-controlled client SNI. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.

CVE-2026-58162
Infra & Gateways
Jul 29, 2026
High7.0Apache

High [CVE-2026-58159] Apache Traffic Server can bypass IP access controls on UDS listeners and through ACL matching errors

Apache Traffic Server can bypass IP access controls on UDS listeners and through ACL matching errors. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.

CVE-2026-58159
Infra & Gateways
Jul 29, 2026
High8.2Apache

High [CVE-2026-58158] Apache Traffic Server mishandles PROXY protocol input, truncating ports and overflowing the stack

Apache Traffic Server mishandles PROXY protocol input, truncating ports and overflowing the stack. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.

CVE-2026-58158
Infra & Gateways
Jul 29, 2026
High8.2Apache

High [CVE-2026-65324] Apache Traffic Server drops the per-stream buffer cap when dechunking HTTP/2 or HTTP/3 responses, letting a slow client exhaust server memory

Apache Traffic Server drops the per-stream buffer cap when dechunking HTTP/2 or HTTP/3 responses, letting a slow client exhaust server memory. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.

CVE-2026-65324
Infra & Gateways
Jul 29, 2026
High8.7Apache

High [CVE-2026-58151] Apache Traffic Server can be crashed or driven to resource exhaustion by abusive HTTP/2 framing and flow-control

Apache Traffic Server can be crashed or driven to resource exhaustion by abusive HTTP/2 framing and flow-control. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.

CVE-2026-58151
Infra & Gateways
Jul 29, 2026
High7.8Apache

High [CVE-2026-58150] Apache Traffic Server does not reject Transfer-Encoding in HTTP/2 requests, allowing downgrade request smuggling

Apache Traffic Server does not reject Transfer-Encoding in HTTP/2 requests, allowing downgrade request smuggling. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.

CVE-2026-58150
Infra & Gateways
Jul 29, 2026
High7.0Apache

High [CVE-2026-57834] Apache Traffic Server allows request smuggling if chunked messages are malformed

Apache Traffic Server allows request smuggling if chunked messages are malformed. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.

CVE-2026-57834
Infra & Gateways
Jul 29, 2026
High8.2Apache

High [CVE-2026-33930] Apache Traffic Server copies the client Host header into a fixed-size stack buffer without a bound during redirect handling, so an over-long Host header overflows the stack when redirect following is enabled

Apache Traffic Server copies the client Host header into a fixed-size stack buffer without a bound during redirect handling, so an over-long Host header overflows the stack when redirect following is enabled. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.

CVE-2026-33930
Infra & Gateways
Jul 29, 2026
High7.7Apache

High [CVE-2026-33267] Improper Input Validation vulnerability in Apache Traffic Server

Improper Input Validation vulnerability in Apache Traffic Server. This issue affects Apache Traffic Server: from 9.2.0 through 9.2.14, from 10.1.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fixes the issue.

CVE-2026-33267
Infra & Gateways
Jul 29, 2026
High7.0Apache

High [CVE-2026-41920] Improper Access Control vulnerability in Apache Traffic Server

Improper Access Control vulnerability in Apache Traffic Server. This issue affects Apache Traffic Server: from 9.0.0 through 9.1.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.1.15 or 10.1.4, which fixes the issue.

CVE-2026-41920
Infra & Gateways
Jul 29, 2026
High7.0Vendor: MediumRed Hat

High [CVE-2026-64556] Detach event groups during remove_on_exec

Detach event groups during remove_on_exec. Red Hat rates this moderate (CVSS 7). Weakness: CWE-663.

CVE-2026-64556
Unclassified
Jul 29, 2026
High7.0Vendor: MediumRed Hat

High [CVE-2026-64557] Fix use-after-free in l2cap_sock_new_connection_cb

Fix use-after-free in l2cap_sock_new_connection_cb(). Red Hat rates this moderate (CVSS 7). Weakness: CWE-825.

CVE-2026-64557
Unclassified
Jul 29, 2026
High7.0Red Hat

High [CVE-2026-64558] Check length in pkey_pckmo handler implementation

Check length in pkey_pckmo handler implementation. Red Hat rates this important (CVSS 7). Weakness: CWE-787.

CVE-2026-64558
Unclassified
Jul 29, 2026
High7.0Vendor: MediumRed Hat

High [CVE-2026-64559] Check length in PKEY_VERIFYPROTK ioctl

Check length in PKEY_VERIFYPROTK ioctl. Red Hat rates this moderate (CVSS 7). Weakness: CWE-805.

CVE-2026-64559
Unclassified
Jul 29, 2026
High7.0Red Hat

High [CVE-2026-64560] Prevent UAF caused by non-leader exec race

Prevent UAF caused by non-leader exec() race. Red Hat rates this important (CVSS 7). Weakness: CWE-364.

CVE-2026-64560
Unclassified
Jul 29, 2026
High7.8Vendor: MediumRed Hat

High [CVE-2026-18107] container escape via rseq critical section hijack during checkpoint/restore

container escape via rseq critical section hijack during checkpoint/restore. Red Hat rates this moderate (CVSS 7.8). Weakness: CWE-269. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 1 more.

CVE-2026-18107
Unclassified
Jul 28, 2026
High7.5Vendor: MediumRed Hat

High [CVE-2026-71190] Unauthenticated denial of service via catastrophic backtracking in Accept header parser

Unauthenticated denial of service via catastrophic backtracking in Accept header parser. Red Hat rates this moderate (CVSS 7.5). Weakness: CWE-1333.

CVE-2026-71190
Unclassified
Jul 28, 2026
High8.2Red Hat

High [CVE-2026-71191] S3API presigned URL unsigned header authorization bypass

S3API presigned URL unsigned header authorization bypass. Red Hat rates this important (CVSS 8.2). Weakness: CWE-863.

CVE-2026-71191
Unclassified
Jul 28, 2026