What is CVE-2026-58157?
CVE-2026-58157 is a vulnerability in Apache Traffic Server where improper reuse of server sessions and tunnels can expose data across different client connections. Affected versions range from 8.0.0 through 10.1.3. Users are advised to upgrade to version 9.2.15 or 10.1.4.
Azərbaycanca: CVE-2026-58157, Apache Traffic Server-də server sessiyalarının və tunellərin səhvən təkrar istifadəsi nəticəsində müxtəlif müştəri bağlantıları arasında məlumat sızmasına səbəb olan boşluqdur. 8.0.0-dən 10.1.3-ə qədər versiyalar təsirlənir. İstifadəçilərə 9.2.15 və ya 10.1.4 versiyalarına yüksəltmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-200; shared vendor: Apache
FAQ2
Which versions of Apache Traffic Server are affected by CVE-2026-58157?
This vulnerability affects Apache Traffic Server versions ranging from 8.0.0 through 10.1.3.
What versions are recommended to upgrade to in order to mitigate CVE-2026-58157?
Users are advised to upgrade to version 9.2.15 or 10.1.4.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.