What is CVE-2026-58189?
CVE-2026-58189 is a redirect-limit bypass vulnerability in Apache Traffic Server where plugins reset the retry counter, enabling SSRF amplification. Affected versions: 8.0.0 through 8.1.9, 9.0.0 through 9.2.14, and 10.0.0 through 10.1.3. Users should upgrade to version 9.2.15 or 10.x.
Azərbaycanca: CVE-2026-58189, Apache Traffic Server-də plaginlərin redirect limitini sıfırlaması səbəbindən redirect-limit bypass zəifliyidir. Bu, SSRF amplification hücumlarına imkan yaradır. Təsirlənən versiyalar: 8.0.0 - 8.1.9, 9.0.0 - 9.2.14, 10.0.0 - 10.1.3; 9.2.15 və ya 10.x versiyalarına yüksəltmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-918; shared vendor: Apache
FAQ2
Which versions of Apache Traffic Server are affected by CVE-2026-58189?
This vulnerability affects Apache Traffic Server versions 8.0.0 through 8.1.9, 9.0.0 through 9.2.14, and 10.0.0 through 10.1.3.
What versions are recommended for upgrading to mitigate CVE-2026-58189?
Users should upgrade to Apache Traffic Server version 9.2.15 or 10.x.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.