PatchSiren cyber security CVE debrief
CVE-2026-58156 Apache CVE debrief
Apache Traffic Server mis-parses ports in URLs and userinfo, allowing port-based access-control bypass. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue. The vulnerability allows for access-control bypass due to improper handling of ports within URLs and userinfo. Affected versions include Apache Traffic Server 8.0.0 through 8.1.9, 9.0.0 through 9.2.14, and 10.0.0 through 10.1.3. The issue can be mitigated by upgrading to version 9.2.15 or 10.1.4. This CVE record and NVD entry provide details on the vulnerability, and users should review official advisories for scope, severity, and guidance.
- Vendor
- Apache
- Product
- Traffic Server
- CVSS
- MEDIUM 6.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-07-29
- Original CVE updated
- 2026-08-03
- Advisory published
- 2026-07-29
- Advisory updated
- 2026-08-03
Who should care
Users of Apache Traffic Server versions 8.0.0 through 8.1.9, 9.0.0 through 9.2.14, and 10.0.0 through 10.1.3 should upgrade to version 9.2.15 or 10.1.4. Operators, platform administrators, vulnerability management teams, and security teams should review the official advisory and CVE record to validate affected scope, severity, and vendor guidance. They should also plan vendor-supported updates or mitigations through normal change control where exposure is confirmed.
Technical summary
The vulnerability allows port-based access-control bypass due to mis-parsing of ports in URLs and userinfo. Affected versions include Apache Traffic Server 8.0.0 through 8.1.9, 9.0.0 through 9.2.14, and 10.0.0 through 10.1.3. The issue can be mitigated by upgrading to version 9.2.15 or 10.1.4, which fix the issue. Users should review and update affected versions and monitor for potential access-control bypass.
Defensive priority
Medium-priority defensive actions are recommended.
Recommended defensive actions
- Upgrade to version 9.2.15 or 10.1.4
- Review and update affected versions
- Monitor for potential access-control bypass
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
- Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance.
- Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed.
- Check relevant monitoring, detection, and logs for exposed assets that need extra review.
Evidence notes
The CVE record and NVD entry provide details on the vulnerability. Evidence is based on official CVE and NVD records. The vulnerability affects Apache Traffic Server versions 8.0.0 through 8.1.9, 9.0.0 through 9.2.14, and 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4. Defenders should verify affected deployments and review official advisories for scope, severity, and guidance.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-58156 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-58156
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-58156 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-58156
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://lists.apache.org/thread/5prl9glcm9g2swnq9hqxvnokylm1gr6d
[email protected] - Vendor Advisory, Mailing List
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.