What is CVE-2026-58161?
CVE-2026-58161 is a vulnerability in Apache Traffic Server that can lead to a crash due to null dereferences and dangling references in TLS and SNI handling. It affects versions 8.0.0 through 8.1.9, 9.0.0 through 9.2.14, and 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4.
Azərbaycanca: CVE-2026-58161 Apache Traffic Server proqramında TLS və SNI emalında baş verən null dereference və dangling reference səhvlərinə görə serverin çökməsinə səbəb olan boşluqdur. 8.0.0-dan 8.1.9-a, 9.0.0-dan 9.2.14-ə və 10.0.0-dan 10.1.3-ə qədər versiyalar təsirlənir. İstifadəçilərə 9.2.15 və ya 10.1.4 versiyalarına yüksəltmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-476; shared vendor: Apache
FAQ2
Which versions of Apache Traffic Server are affected by CVE-2026-58161?
This vulnerability affects versions 8.0.0 through 8.1.9, 9.0.0 through 9.2.14, and 10.0.0 through 10.1.3.
What upgrades are recommended to fix CVE-2026-58161?
Users are recommended to upgrade to version 9.2.15 or 10.1.4.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.