Skip to content
VulniPulse

Apache Software Foundation Infra (APISIX/Traffic Server/CloudStack) Vulnerabilities & Security Advisories

44 advisories tracked · ASF Security (security@apache.org CNA) via NVD · 0 listed in the CISA Known Exploited Vulnerabilities catalog

Every row below is a published Apache Software Foundation advisory that VulniPulse classified as Infra (APISIX/Traffic Server/CloudStack), with the CVEs, affected and fixed releases and exploitation status the vendor stated. Severity mix: 5 critical, 28 high, 11 medium.

Android app · Google Play

Monitor Apache CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Source

ASF Security (security@apache.org CNA) via NVD

The Apache Software Foundation is its own CVE Numbering Authority: every Apache project CVE (HTTP Server, Tomcat, ActiveMQ, Struts, Kafka, Airflow, OFBiz, Solr and 300+ more) is published by security@apache.org and announced on the projects' mailing lists. VulniPulse ingests the CNA feed from NVD filtered to security@apache.org — official, machine-readable, with affected/fixed versions embedded in each description. Per-project security pages (httpd.apache.org/security, tomcat.apache.org/security-XX.html) carry the vendor detail.

Latest Apache Infra (APISIX/Traffic Server/CloudStack) advisories

Critical9.2Apache Updated

Critical [CVE-2026-58179] The Apache Traffic Server regex_remap plugin overflows the stack and integers from substitution input

The Apache Traffic Server regex_remap plugin overflows the stack and integers from substitution input. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.

CVE-2026-58179
Infra & Gateways
Jul 29, 2026
Critical9.2Apache Updated

Critical [CVE-2026-58161] Apache Traffic Server can crash from null dereferences and dangling references in TLS and SNI handling

Apache Traffic Server can crash from null dereferences and dangling references in TLS and SNI handling. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.

CVE-2026-58161
Infra & Gateways
Jul 29, 2026
Critical9.2Apache Updated

Critical [CVE-2026-58155] Apache Traffic Server truncates over-long header names, allowing header aliasing, request smuggling, and policy bypass

Apache Traffic Server truncates over-long header names, allowing header aliasing, request smuggling, and policy bypass. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.

CVE-2026-58155
Infra & Gateways
Jul 29, 2026
Critical9.2Apache Updated

Critical [CVE-2026-58154] Apache Traffic Server can write out of bounds or overflow integers while parsing MIME and HTTP headers

Apache Traffic Server can write out of bounds or overflow integers while parsing MIME and HTTP headers. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.

CVE-2026-58154
Infra & Gateways
Jul 29, 2026
High8.2Apache Updated

High [CVE-2026-58189] Apache Traffic Server allows redirect-limit bypass when plugins reset the retry counter, enabling SSRF amplification

Apache Traffic Server allows redirect-limit bypass when plugins reset the retry counter, enabling SSRF amplification. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.

CVE-2026-58189
Infra & Gateways
Jul 29, 2026
High8.4Apache Updated

High [CVE-2026-58188] Several Apache Traffic Server experimental plugins have memory-safety and limit-bypass errors

Several Apache Traffic Server experimental plugins have memory-safety and limit-bypass errors. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.

CVE-2026-58188
Infra & Gateways
Jul 29, 2026
High8.2Apache Updated

High [CVE-2026-58186] The Apache Traffic Server webp_transform plugin can decode unsafely and serve mislabeled, cacheable responses

The Apache Traffic Server webp_transform plugin can decode unsafely and serve mislabeled, cacheable responses. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.

CVE-2026-58186
Infra & Gateways
Jul 29, 2026
High8.2Apache Updated

High [CVE-2026-58185] The Apache Traffic Server intercept plugin has a use-after-free

The Apache Traffic Server intercept plugin has a use-after-free. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.

CVE-2026-58185
Infra & Gateways
Jul 29, 2026
High8.3Apache Updated

High [CVE-2026-58184] The Apache Traffic Server header_rewrite plugin

The Apache Traffic Server header_rewrite plugin can crash or corrupt memory during cookie operations and CIDR condition matching. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.

CVE-2026-58184
Infra & Gateways
Jul 29, 2026
High8.2Apache Updated

High [CVE-2026-58183] The Apache Traffic Server prefetch plugin can crash when processing attacker-influenced input

The Apache Traffic Server prefetch plugin can crash when processing attacker-influenced input. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.

CVE-2026-58183
Infra & Gateways
Jul 29, 2026
High8.2Apache Updated

High [CVE-2026-58182] The Apache Traffic Server ts_lua plugin mishandles initialization, transform context, and per-instance state

The Apache Traffic Server ts_lua plugin mishandles initialization, transform context, and per-instance state. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.

CVE-2026-58182
Infra & Gateways
Jul 29, 2026
High8.2Apache Updated

High [CVE-2026-58181] The Apache Traffic Server uri_signing and url_sig plugins can exhaust the stack or crash on attacker input

The Apache Traffic Server uri_signing and url_sig plugins can exhaust the stack or crash on attacker input. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.

CVE-2026-58181
Infra & Gateways
Jul 29, 2026
High8.2Apache Updated

High [CVE-2026-58180] The Apache Traffic Server txn_box plugin overflows the stack from attacker-controlled input

The Apache Traffic Server txn_box plugin overflows the stack from attacker-controlled input. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.

CVE-2026-58180
Infra & Gateways
Jul 29, 2026
High8.2Apache Updated

High [CVE-2026-58178] The Apache Traffic Server ESI plugin can recurse without bound and fetch attacker-controlled URLs

The Apache Traffic Server ESI plugin can recurse without bound and fetch attacker-controlled URLs. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.

CVE-2026-58178
Infra & Gateways
Jul 29, 2026
High8.3Apache Updated

High [CVE-2026-58177] The Apache Traffic Server Cripts framework has out-of-bounds writes, path traversal, and use-after-free errors

The Apache Traffic Server Cripts framework has out-of-bounds writes, path traversal, and use-after-free errors. This issue affects Apache Traffic Server: from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 10.1.4, which fix the issue.

CVE-2026-58177
Infra & Gateways
Jul 29, 2026
High8.2Apache Updated

High [CVE-2026-58175] Apache Traffic Server leaks memory when handling HostDB SRV records

Apache Traffic Server leaks memory when handling HostDB SRV records. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.

CVE-2026-58175
Infra & Gateways
Jul 29, 2026
High8.3Apache Updated

High [CVE-2026-58164] Apache Traffic Server has use-after-free and time-of-check/time-of-use errors in remap configuration handling

Apache Traffic Server has use-after-free and time-of-check/time-of-use errors in remap configuration handling. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.

CVE-2026-58164
Infra & Gateways
Jul 29, 2026
High8.3Apache Updated

High [CVE-2026-58163] Apache Traffic Server mishandles on-disk cache fields and object lifetimes, corrupting state or crashing

Apache Traffic Server mishandles on-disk cache fields and object lifetimes, corrupting state or crashing. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.

CVE-2026-58163
Infra & Gateways
Jul 29, 2026
High8.4Apache Updated

High [CVE-2026-58162] The Apache Traffic Server certifier plugin generates certificates based on attacker-controlled client SNI

The Apache Traffic Server certifier plugin generates certificates based on attacker-controlled client SNI. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.

CVE-2026-58162
Infra & Gateways
Jul 29, 2026
High7.0Apache Updated

High [CVE-2026-58159] Apache Traffic Server can bypass IP access controls on UDS listeners and through ACL matching errors

Apache Traffic Server can bypass IP access controls on UDS listeners and through ACL matching errors. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.

CVE-2026-58159
Infra & Gateways
Jul 29, 2026

← All Apache advisories