Skip to content
VulniPulse

Apache Software Foundation Infra (APISIX/Traffic Server/CloudStack) Vulnerabilities & Security Advisories

44 advisories tracked · ASF Security (security@apache.org CNA) via NVD · 0 listed in the CISA Known Exploited Vulnerabilities catalog

Every row below is a published Apache Software Foundation advisory that VulniPulse classified as Infra (APISIX/Traffic Server/CloudStack), with the CVEs, affected and fixed releases and exploitation status the vendor stated. Severity mix: 5 critical, 28 high, 11 medium.

Android app · Google Play

Monitor Apache CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Source

ASF Security (security@apache.org CNA) via NVD

The Apache Software Foundation is its own CVE Numbering Authority: every Apache project CVE (HTTP Server, Tomcat, ActiveMQ, Struts, Kafka, Airflow, OFBiz, Solr and 300+ more) is published by security@apache.org and announced on the projects' mailing lists. VulniPulse ingests the CNA feed from NVD filtered to security@apache.org — official, machine-readable, with affected/fixed versions embedded in each description. Per-project security pages (httpd.apache.org/security, tomcat.apache.org/security-XX.html) carry the vendor detail.

Latest Apache Infra (APISIX/Traffic Server/CloudStack) advisories

High8.2Apache Updated

High [CVE-2026-58158] Apache Traffic Server mishandles PROXY protocol input, truncating ports and overflowing the stack

Apache Traffic Server mishandles PROXY protocol input, truncating ports and overflowing the stack. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.

CVE-2026-58158
Infra & Gateways
Jul 29, 2026
High8.2Apache Updated

High [CVE-2026-65324] Apache Traffic Server drops the per-stream buffer cap

Apache Traffic Server drops the per-stream buffer cap when dechunking HTTP/2 or HTTP/3 responses, letting a slow client exhaust server memory. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.

CVE-2026-65324
Infra & Gateways
Jul 29, 2026
High8.7Apache Updated

High [CVE-2026-58151] Apache Traffic Server can be crashed or driven to resource exhaustion by abusive HTTP/2 framing and flow-control

Apache Traffic Server can be crashed or driven to resource exhaustion by abusive HTTP/2 framing and flow-control. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.

CVE-2026-58151
Infra & Gateways
Jul 29, 2026
High7.8Apache Updated

High [CVE-2026-58150] Apache Traffic Server does not reject Transfer-Encoding in HTTP/2 requests, allowing downgrade request smuggling

Apache Traffic Server does not reject Transfer-Encoding in HTTP/2 requests, allowing downgrade request smuggling. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.

CVE-2026-58150
Infra & Gateways
Jul 29, 2026
High7.0Apache Updated

High [CVE-2026-57834] Apache Traffic Server allows request smuggling if chunked messages are malformed

Apache Traffic Server allows request smuggling if chunked messages are malformed. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.

CVE-2026-57834
Infra & Gateways
Jul 29, 2026
High8.2Apache Updated

High [CVE-2026-33930] Apache Traffic Server copies the client Host header into a fixed-size stack buffer without a bound during redirect…

Apache Traffic Server copies the client Host header into a fixed-size stack buffer without a bound during redirect handling, so an over-long Host header overflows the stack when redirect following is enabled. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.

CVE-2026-33930
Infra & Gateways
Jul 29, 2026
High7.7Apache Updated

High [CVE-2026-33267] Improper Input Validation vulnerability in Apache Traffic Server

Improper Input Validation vulnerability in Apache Traffic Server. This issue affects Apache Traffic Server: from 9.2.0 through 9.2.14, from 10.1.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fixes the issue.

CVE-2026-33267
Infra & Gateways
Jul 29, 2026
High7.0Apache Updated

High [CVE-2026-41920] Improper Access Control vulnerability in Apache Traffic Server

Improper Access Control vulnerability in Apache Traffic Server. This issue affects Apache Traffic Server: from 9.0.0 through 9.1.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.1.15 or 10.1.4, which fixes the issue.

CVE-2026-41920
Infra & Gateways
Jul 29, 2026
Medium6.3Apache Updated

Medium [CVE-2026-65100] Apache Traffic Server updates the HTTP/2 HPACK dynamic table before confirming the header block encoded successfully…

Apache Traffic Server updates the HTTP/2 HPACK dynamic table before confirming the header block encoded successfully, so an encode failure leaves the encoder out of sync with the peer decoder and corrupts subsequent header blocks on the connection. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.

CVE-2026-65100
Infra & Gateways
Jul 29, 2026
Medium6.3Apache Updated

Medium [CVE-2026-58187] The Apache Traffic Server multiplexer plugin overruns its chunk-decode buffer on upstream input, enabling denial of…

The Apache Traffic Server multiplexer plugin overruns its chunk-decode buffer on upstream input, enabling denial of service. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.

CVE-2026-58187
Infra & Gateways
Jul 29, 2026
Medium6.3Apache Updated

Medium [CVE-2026-58160] Apache Traffic Server reads out of bounds while parsing DNS answers

Apache Traffic Server reads out of bounds while parsing DNS answers. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.

CVE-2026-58160
Infra & Gateways
Jul 29, 2026
Medium6.9Apache Updated

Medium [CVE-2026-58157] Apache Traffic Server can reuse server sessions and tunnels improperly, exposing data across client connections

Apache Traffic Server can reuse server sessions and tunnels improperly, exposing data across client connections. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.

CVE-2026-58157
Infra & Gateways
Jul 29, 2026
Medium6.3Apache Updated

Medium [CVE-2026-58156] Apache Traffic Server mis-parses ports in URLs and userinfo, allowing port-based access-control bypass

Apache Traffic Server mis-parses ports in URLs and userinfo, allowing port-based access-control bypass. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.

CVE-2026-58156
Infra & Gateways
Jul 29, 2026
Medium6.3Apache Updated

Medium [CVE-2026-65325] Apache Traffic Server reuses multiplexed HTTP/2 origin connections without verifying the server certificate covers the…

Apache Traffic Server reuses multiplexed HTTP/2 origin connections without verifying the server certificate covers the new request hostname. This issue affects Apache Traffic Server: from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.

CVE-2026-65325
Infra & Gateways
Jul 29, 2026
Medium6.3Apache Updated

Medium [CVE-2026-58153] Apache Traffic Server forwards HTTP/2 origin trailers to HTTP/1 clients without proper chunked framing

Apache Traffic Server forwards HTTP/2 origin trailers to HTTP/1 clients without proper chunked framing when converting HTTP/2 to HTTP/1. This issue affects Apache Traffic Server: from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.

CVE-2026-58153
Infra & Gateways
Jul 29, 2026
Medium6.9Apache Updated

Medium [CVE-2026-58152] Apache Traffic Server mishandles integers while decoding HPACK/XPACK headers, corrupting memory

Apache Traffic Server mishandles integers while decoding HPACK/XPACK headers, corrupting memory. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.

CVE-2026-58152
Infra & Gateways
Jul 29, 2026
Medium6.9Apache Updated

Medium [CVE-2026-24033] Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') vulnerability in Apache Traffic Server

Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') vulnerability in Apache Traffic Server. This issue affects Apache Traffic Server: from 10.0.0 through 10.1.3, from 9.0.0 through 9.2.14. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fixes the issue.

CVE-2026-24033
Infra & Gateways
Jul 29, 2026
Medium6.9Apache Updated

Medium [CVE-2026-22068] Regular Expression without Anchors vulnerability in Apache Traffic Server

Regular Expression without Anchors vulnerability in Apache Traffic Server. This issue affects Apache Traffic Server: from 10.0.X through 10.1.3, from 9.0.X through 9.2.14. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fixes the issue.

CVE-2026-22068
Infra & Gateways
Jul 29, 2026
High7.5Apache

High [CVE-2026-59173] Uncontrolled Resource Consumption vulnerability in Apache Traffic Server

Uncontrolled Resource Consumption vulnerability in Apache Traffic Server. This issue affects Apache Traffic Server: from 9.0.0 through 9.1.13, from 10.0.0 through 10.1.2. Users are recommended to upgrade to version 9.1.14 or 10.1.3, which fixes the issue.

CVE-2026-59173
Infra & Gateways
Jul 18, 2026
Critical9.1Apache

Critical [CVE-2026-31908] Apache APISIX: Header injection vulnerability in Apache APISIX.

Header injection vulnerability in Apache APISIX. The attacker can take advantage of certain configuration in forward-auth plugin to inject malicious headers. This issue affects Apache APISIX: from 2.12.0 through 3.15.0. Users are recommended to upgrade to version 3.16.0, which fixes the issue.

CVE-2026-31908
Infra & Gateways
Apr 14, 2026

← All Apache advisories