PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-58156 Apache CVE debrief

Apache Traffic Server mis-parses ports in URLs and userinfo, allowing port-based access-control bypass. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue. The vulnerability allows for access-control bypass due to improper handling of ports within URLs and userinfo. Affected versions include Apache Traffic Server 8.0.0 through 8.1.9, 9.0.0 through 9.2.14, and 10.0.0 through 10.1.3. The issue can be mitigated by upgrading to version 9.2.15 or 10.1.4. This CVE record and NVD entry provide details on the vulnerability, and users should review official advisories for scope, severity, and guidance.

Vendor
Apache
Product
Traffic Server
CVSS
MEDIUM 6.3
CISA KEV
Not listed in stored evidence
Original CVE published
2026-07-29
Original CVE updated
2026-08-03
Advisory published
2026-07-29
Advisory updated
2026-08-03

Who should care

Users of Apache Traffic Server versions 8.0.0 through 8.1.9, 9.0.0 through 9.2.14, and 10.0.0 through 10.1.3 should upgrade to version 9.2.15 or 10.1.4. Operators, platform administrators, vulnerability management teams, and security teams should review the official advisory and CVE record to validate affected scope, severity, and vendor guidance. They should also plan vendor-supported updates or mitigations through normal change control where exposure is confirmed.

Technical summary

The vulnerability allows port-based access-control bypass due to mis-parsing of ports in URLs and userinfo. Affected versions include Apache Traffic Server 8.0.0 through 8.1.9, 9.0.0 through 9.2.14, and 10.0.0 through 10.1.3. The issue can be mitigated by upgrading to version 9.2.15 or 10.1.4, which fix the issue. Users should review and update affected versions and monitor for potential access-control bypass.

Defensive priority

Medium-priority defensive actions are recommended.

Recommended defensive actions

  • Upgrade to version 9.2.15 or 10.1.4
  • Review and update affected versions
  • Monitor for potential access-control bypass
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
  • Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance.
  • Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed.
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review.

Evidence notes

The CVE record and NVD entry provide details on the vulnerability. Evidence is based on official CVE and NVD records. The vulnerability affects Apache Traffic Server versions 8.0.0 through 8.1.9, 9.0.0 through 9.2.14, and 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4. Defenders should verify affected deployments and review official advisories for scope, severity, and guidance.

Official resources

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-29T09:16:30.023Z and has not been modified since then.