What is CVE-2026-58178?
A vulnerability in the Apache Traffic Server ESI plugin allows unbounded recursion and fetching of attacker-controlled URLs. Affected versions include 8.0.0 through 8.1.9, 9.0.0 through 9.2.14, and 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4 to remediate the issue.
Azərbaycanca: Apache Traffic Server-in ESI plugin-ində sərhədsiz rekursiya (unbounded recursion) zəifliyi aşkarlanıb. Bu, təcavüzkara uzaqdan idarə olunan URL-lərə sorğu göndərməyə imkan verir. 8.0.0-8.1.9, 9.0.0-9.2.14 və 10.0.0-10.1.3 versiyaları təsirlənir; istifadəçilərə dərhal 9.2.15 və ya 10.1.4 versiyalarına yüksəltmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-918; shared vendor: Apache
FAQ2
Which component of Apache Traffic Server is affected by CVE-2026-58178?
CVE-2026-58178 affects the ESI plugin of Apache Traffic Server.
To which versions should users upgrade to remediate CVE-2026-58178?
Users are recommended to upgrade to Apache Traffic Server version 9.2.15 or 10.1.4 to remediate CVE-2026-58178.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.