What is CVE-2026-58159?
CVE-2026-58159 allows bypassing IP access controls in Apache Traffic Server via Unix Domain Socket (UDS) listeners and ACL match errors. This vulnerability affects versions from 8.0.0 through 10.1.3, and users are recommended to upgrade to version 9.2.15 or 10.1.4.
Azərbaycanca: CVE-2026-58159 Apache Traffic Server-də IP giriş nəzarətinin Unix Domain Socket (UDS) listener-ləri və ACL uyğunlaşma səhvləri vasitəsilə keçilməsinə imkan yaradır. Bu zəiflik 8.0.0-dən 10.1.3-ə qədər bir neçə versiyanı təsirləndirir, istifadəçilərə 9.2.15 və ya 10.1.4 versiyalarına yüksəltmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-863; shared vendor: Apache
FAQ2
Which versions of Apache Traffic Server are affected by CVE-2026-58159?
This vulnerability affects Apache Traffic Server versions from 8.0.0 through 10.1.3.
What upgrades are recommended for CVE-2026-58159?
Users are recommended to upgrade to Apache Traffic Server version 9.2.15 or 10.1.4.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.