What is CVE-2026-58150?
This CVE describes an HTTP Request Smuggling vulnerability in Apache Traffic Server, caused by its failure to reject the Transfer-Encoding header in HTTP/2 requests. The issue affects versions 8.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4.
Azərbaycanca: Bu CVE, Apache Traffic Server-in HTTP/2 sorğularında Transfer-Encoding başlığını rədd etməməsi nəticəsində yaranan HTTP Request Smuggling zəifliyidir. Bu qüsur, serverin 8.0.0-dən 10.1.3 versiyalarına qədər təsir edir. İstifadəçilərə 9.2.15 və ya 10.1.4 versiyalarına yüksəltmək tövsiyə olunur.
Related CVEs
link basis: shared vendor: Apache
FAQ2
Which versions of Apache Traffic Server are affected by CVE-2026-58150?
This vulnerability affects Apache Traffic Server versions 8.0.0 through 10.1.3.
What action is recommended to mitigate the HTTP Request Smuggling vulnerability described in CVE-2026-58150?
Users are recommended to upgrade Apache Traffic Server to version 9.2.15 or 10.1.4.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.