Skip to content
VulniPulse

Apache Software Foundation Infra (APISIX/Traffic Server/CloudStack) Vulnerabilities & Security Advisories

44 advisories tracked · ASF Security (security@apache.org CNA) via NVD · 0 listed in the CISA Known Exploited Vulnerabilities catalog

Every row below is a published Apache Software Foundation advisory that VulniPulse classified as Infra (APISIX/Traffic Server/CloudStack), with the CVEs, affected and fixed releases and exploitation status the vendor stated. Severity mix: 5 critical, 28 high, 11 medium.

Android app · Google Play

Monitor Apache CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Source

ASF Security (security@apache.org CNA) via NVD

The Apache Software Foundation is its own CVE Numbering Authority: every Apache project CVE (HTTP Server, Tomcat, ActiveMQ, Struts, Kafka, Airflow, OFBiz, Solr and 300+ more) is published by security@apache.org and announced on the projects' mailing lists. VulniPulse ingests the CNA feed from NVD filtered to security@apache.org — official, machine-readable, with affected/fixed versions embedded in each description. Per-project security pages (httpd.apache.org/security, tomcat.apache.org/security-XX.html) carry the vendor detail.

Latest Apache Infra (APISIX/Traffic Server/CloudStack) advisories

Critical9.2Apache Updated

Critical [CVE-2026-58179] The Apache Traffic Server regex_remap plugin overflows the stack and integers from substitution input

The Apache Traffic Server regex_remap plugin overflows the stack and integers from substitution input. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.

CVE-2026-58179
Infra & Gateways
Jul 29, 2026
Critical9.2Apache Updated

Critical [CVE-2026-58161] Apache Traffic Server can crash from null dereferences and dangling references in TLS and SNI handling

Apache Traffic Server can crash from null dereferences and dangling references in TLS and SNI handling. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.

CVE-2026-58161
Infra & Gateways
Jul 29, 2026
Critical9.2Apache Updated

Critical [CVE-2026-58155] Apache Traffic Server truncates over-long header names, allowing header aliasing, request smuggling, and policy bypass

Apache Traffic Server truncates over-long header names, allowing header aliasing, request smuggling, and policy bypass. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.

CVE-2026-58155
Infra & Gateways
Jul 29, 2026
Critical9.2Apache Updated

Critical [CVE-2026-58154] Apache Traffic Server can write out of bounds or overflow integers while parsing MIME and HTTP headers

Apache Traffic Server can write out of bounds or overflow integers while parsing MIME and HTTP headers. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.

CVE-2026-58154
Infra & Gateways
Jul 29, 2026
Critical9.1Apache

Critical [CVE-2026-31908] Apache APISIX: Header injection vulnerability in Apache APISIX.

Header injection vulnerability in Apache APISIX. The attacker can take advantage of certain configuration in forward-auth plugin to inject malicious headers. This issue affects Apache APISIX: from 2.12.0 through 3.15.0. Users are recommended to upgrade to version 3.16.0, which fixes the issue.

CVE-2026-31908
Infra & Gateways
Apr 14, 2026

← All Apache advisories