CVE-2026-58156
MEDIUM SEVERITYCVSS Score & Metrics
Base Score
4.9 / 10
Vector String
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:L/A:N
Vulnerability Description
Apache Traffic Server mis-parses ports in URLs and userinfo, allowing port-based access-control bypass.
This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3.
Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.
This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3.
Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.
Vulnerability Details
Published Date
Last Modified
CWE ID
CWE-863
Source
NVD
Vendor
Apache Software Foundation
Product
Apache Traffic Server
Discussion (0)
Add Comment
No comments yet. Be the first!