PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-58156 Apache CVE debrief

Apache Traffic Server mis-parses ports in URLs and userinfo, allowing port-based access-control bypass. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue. The vulnerability allows for access-control bypass due to improper handling of ports within URLs and userinfo. Affected versions include Apache Traffic Server 8.0.0 through 8.1.9, 9.0.0 through 9.2.14, and 10.0.0 through 10.1.3. The issue can be mitigated by upgrading to version 9.2.15 or 10.1.4. This CVE record and NVD entry provide details on the vulnerability, and users should review official advisories for scope, severity, and guidance.

Vendor
Apache
Product
Traffic Server
CVSS
MEDIUM 6.3
CISA KEV
Not listed in stored evidence
Original CVE published
2026-07-29
Original CVE updated
2026-08-03
Advisory published
2026-07-29
Advisory updated
2026-08-03

Who should care

Users of Apache Traffic Server versions 8.0.0 through 8.1.9, 9.0.0 through 9.2.14, and 10.0.0 through 10.1.3 should upgrade to version 9.2.15 or 10.1.4. Operators, platform administrators, vulnerability management teams, and security teams should review the official advisory and CVE record to validate affected scope, severity, and vendor guidance. They should also plan vendor-supported updates or mitigations through normal change control where exposure is confirmed.

Technical summary

The vulnerability allows port-based access-control bypass due to mis-parsing of ports in URLs and userinfo. Affected versions include Apache Traffic Server 8.0.0 through 8.1.9, 9.0.0 through 9.2.14, and 10.0.0 through 10.1.3. The issue can be mitigated by upgrading to version 9.2.15 or 10.1.4, which fix the issue. Users should review and update affected versions and monitor for potential access-control bypass.

Defensive priority

Medium-priority defensive actions are recommended.

Recommended defensive actions

  • Upgrade to version 9.2.15 or 10.1.4
  • Review and update affected versions
  • Monitor for potential access-control bypass
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
  • Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance.
  • Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed.
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review.

Evidence notes

The CVE record and NVD entry provide details on the vulnerability. Evidence is based on official CVE and NVD records. The vulnerability affects Apache Traffic Server versions 8.0.0 through 8.1.9, 9.0.0 through 9.2.14, and 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4. Defenders should verify affected deployments and review official advisories for scope, severity, and guidance.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-58156 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-58156

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-58156 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-58156

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.