What is CVE-2026-58152?
Apache Traffic Server mishandles integers during HPACK/XPACK header decoding, leading to memory corruption. This impacts versions from 8.0.0 through 8.1.9, 9.0.0 through 9.2.14, and 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4.
Azərbaycanca: Apache Traffic Server-in HPACK/XPACK başlıqlarının dekodlanması zamanı tam ədədlərin səhv işlənməsi nəticəsində yaddaş korrupsiyası baş verir. Bu problem 8.0.0-dən 8.1.9-a, 9.0.0-dən 9.2.14-ə, 10.0.0-dən 10.1.3-ə qədər versiyalara təsir edir. İstifadəçilərə 9.2.15 və ya 10.1.4 versiyalarına yenilənmə tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-190; shared vendor: Apache
FAQ2
Which versions of Apache Traffic Server are vulnerable to CVE-2026-58152?
This vulnerability impacts versions from 8.0.0 through 8.1.9, 9.0.0 through 9.2.14, and 10.0.0 through 10.1.3.
What action is recommended to mitigate CVE-2026-58152?
Users are recommended to upgrade to Apache Traffic Server version 9.2.15 or 10.1.4.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.