What is CVE-2026-58162?
The Apache Traffic Server certifier plugin generates certificates based on attacker-controlled client SNI. This issue affects Apache Traffic Server versions 8.0.0 through 8.1.9, 9.0.0 through 9.2.14, and 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4.
Azərbaycanca: Apache Traffic Server-in certifier plaqini müştəri tərəfindən idarə olunan SNI əsasında yanlış sertifikat generasiya edir. Bu, Apache Traffic Server 8.0.0-dən 8.1.9, 9.0.0-dən 9.2.14, 10.0.0-dən 10.1.3 versiyalarına təsir göstərir. İstifadəçilərə 9.2.15 və ya 10.1.4 versiyalarına yüksəltmək tövsiyə olunur.
Related CVEs
link basis: shared vendor: Apache
FAQ2
Which versions of Apache Traffic Server are affected by CVE-2026-58162?
This vulnerability affects Apache Traffic Server versions 8.0.0 through 8.1.9, 9.0.0 through 9.2.14, and 10.0.0 through 10.1.3.
What upgrades are recommended to mitigate CVE-2026-58162?
Users are recommended to upgrade to version 9.2.15 or 10.1.4.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.