PatchSiren

Apache CVE debriefs · Page 2

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH Apache CVE published 2026-07-29

CVE-2026-58181

Apache Traffic Server's uri_signing and url_sig plugins can crash or exhaust the stack with attacker input, affecting versions 8.0.0 through 8.1.9, 9.0.0 through 9.2.14, and 10.0.0 through 10.1.3. This issue presents a high severity vulnerability, with a CVSS score of 8.2, and users are strongly advised to upgrade to version 9.2.15 or 10.1.4. The vulnerability allows for potential crashes or stack exhaust [truncated]

HIGH Apache CVE published 2026-07-29

CVE-2026-58180

The Apache Traffic Server txn_box plugin is vulnerable to a stack overflow attack from attacker-controlled input. This issue affects Apache Traffic Server versions 8.0.0 through 8.1.9, 9.0.0 through 9.2.14, and 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue. The affected product or component is Apache Traffic Server, and the vulnerability class is [truncated]

HIGH Apache CVE published 2026-07-29

CVE-2026-58178

Apache Traffic Server ESI plugin vulnerability allows for unbounded recursion and fetching of attacker-controlled URLs. This issue affects Apache Traffic Server versions 8.0.0 through 8.1.9, 9.0.0 through 9.2.14, and 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4. The vulnerability is due to a lack of proper bounds checking in the ESI plugin, which allows an attacker t [truncated]

HIGH Apache CVE published 2026-07-29

CVE-2026-58177

Apache Traffic Server has out-of-bounds writes, path traversal, and use-after-free errors in its Cripts framework. This issue affects Apache Traffic Server from version 10.0.0 through 10.1.3. Users are recommended to upgrade to version 10.1.4, which fixes the issue. The vulnerability's technical details indicate that it could lead to significant impact if exploited, given its high CVSS score of 8.3 and HI [truncated]

HIGH Apache CVE published 2026-07-29

CVE-2026-58175

Apache Traffic Server leaks memory when handling HostDB SRV records. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue. The vulnerability could lead to performance issues or crashes if exploited. Defenders should review official CVE records, assess depl [truncated]

HIGH Apache CVE published 2026-07-29

CVE-2026-58164

Apache Traffic Server has use-after-free and time-of-check/time-of-use errors in remap configuration handling. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue. The vulnerability could allow a remote attacker to potentially execute arbitrary code. Oper [truncated]

CRITICAL Apache CVE published 2026-07-29

CVE-2026-58161

Apache Traffic Server can crash from null dereferences and dangling references in TLS and SNI handling. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue. The vulnerability is considered critical, with a CVSS score of 9.2, and can lead to crashes and po [truncated]

MEDIUM Apache CVE published 2026-07-29

CVE-2026-58160

Apache Traffic Server is vulnerable to an out-of-bounds read while parsing DNS answers. This issue affects Apache Traffic Server versions from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, and from 10.0.0 through 10.1.3. The vulnerability allows attackers to read beyond the bounds of the DNS answer buffer, potentially leading to information disclosure. Users are recommended to upgrade to version 9.2.15 [truncated]

HIGH Apache CVE published 2026-07-29

CVE-2026-58159

Apache Traffic Server has a vulnerability allowing IP access controls to be bypassed on UDS listeners due to ACL matching errors. This affects versions 8.0.0 through 8.1.9, 9.0.0 through 9.2.14, and 10.0.0 through 10.1.3. The issue allows unauthorized access and potential security breaches. Users of Apache Traffic Server, especially those with high security requirements or using versions within the affect [truncated]

HIGH Apache CVE published 2026-07-29

CVE-2026-58158

Apache Traffic Server, a high-performance caching proxy server, is vulnerable to a stack overflow issue due to mishandling of PROXY protocol input. This vulnerability, affecting versions 8.0.0 through 8.1.9, 9.0.0 through 9.2.14, and 10.0.0 through 10.1.3, could allow attackers to execute arbitrary code or disrupt service, emphasizing the need for prompt patching. Users are recommended to upgrade to versi [truncated]

MEDIUM Apache CVE published 2026-07-29

CVE-2026-58157

Apache Traffic Server can improperly reuse server sessions and tunnels, exposing data across client connections. This issue affects Apache Traffic Server versions 8.0.0 through 8.1.9, 9.0.0 through 9.2.14, and 10.0.0 through 10.1.3. The vulnerability allows for the improper reuse of server sessions and tunnels, potentially leading to data exposure across client connections. Users are recommended to upgrad [truncated]

HIGH Apache CVE published 2026-07-29

CVE-2026-23904

The CVE-2026-23904 vulnerability affects Apache Kyuubi, specifically versions from 1.8.0 before 1.12.0. This vulnerability allows a remote requester to cause the Kyuubi server to send HTTP requests to arbitrary reachable hosts, potentially leading to Server-Side Request Forgery (SSRF) or open-proxy behavior. The vulnerability is addressed by upgrading to version 1.12.0, which disables the proxy by default [truncated]

MEDIUM Apache CVE published 2026-07-29

CVE-2026-65325

Apache Traffic Server reuses multiplexed HTTP/2 origin connections without verifying the server certificate covers the new request hostname. This issue affects Apache Traffic Server: from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue. The vulnerability allows for potential security risks if not addressed. It is crucial t [truncated]

HIGH Apache CVE published 2026-07-29

CVE-2026-65324

Apache Traffic Server drops the per-stream buffer cap when dechunking HTTP/2 or HTTP/3 responses, letting a slow client exhaust server memory. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue. The vulnerability can lead to a denial-of-service (DoS) con [truncated]

MEDIUM Apache CVE published 2026-07-29

CVE-2026-58156

Apache Traffic Server mis-parses ports in URLs and userinfo, allowing port-based access-control bypass. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue. The vulnerability allows for access-control bypass due to improper handling of ports within URLs a [truncated]

CRITICAL Apache CVE published 2026-07-29

CVE-2026-58155

Apache Traffic Server is vulnerable to header aliasing, request smuggling, and policy bypass due to truncation of over-long header names. This issue affects Apache Traffic Server versions from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, and from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4 to fix the issue.

CRITICAL Apache CVE published 2026-07-29

CVE-2026-58154

Apache Traffic Server can write out of bounds or overflow integers while parsing MIME and HTTP headers. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue. The vulnerability has been publicly disclosed and is considered critical. Affected systems may exp [truncated]

MEDIUM Apache CVE published 2026-07-29

CVE-2026-58153

Apache Traffic Server vulnerability CVE-2026-58153 allows for HTTP/2 origin trailers to be forwarded to HTTP/1 clients without proper chunked framing. This issue affects Apache Traffic Server versions from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue. The vulnerability occurs when Apache Traffic Server converts HTTP/2 requests to HTTP/1 requests, [truncated]

HIGH Apache CVE published 2026-07-29

CVE-2026-58150

Apache Traffic Server does not reject Transfer-Encoding in HTTP/2 requests, allowing downgrade request smuggling. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue. The vulnerability allows for potential request smuggling attacks due to the improper han [truncated]

HIGH Apache CVE published 2026-07-29

CVE-2026-57834

Apache Traffic Server is vulnerable to request smuggling when chunked messages are malformed. This issue affects Apache Traffic Server versions from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, and from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue. The vulnerability allows attackers to bypass security controls and access sensitive data. It is [truncated]

HIGH Apache CVE published 2026-07-29

CVE-2026-41920

Apache Traffic Server Improper Access Control vulnerability CVE-2026-41920 affects versions 9.0.0 through 9.1.14 and 10.0.0 through 10.1.3. The vendor advises upgrading to version 9.1.15 or 10.1.4 to address the issue. This Improper Access Control vulnerability can lead to unauthorized access and potential security breaches in Apache Traffic Server installations. Security teams should review and apply the [truncated]

HIGH Apache CVE published 2026-07-29

CVE-2026-33930

Apache Traffic Server is vulnerable to a stack overflow during redirect handling when following redirects is enabled, caused by copying the client Host header into a fixed-size stack buffer without bounds checking. This issue affects Apache Traffic Server versions from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, and from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1 [truncated]

HIGH Apache CVE published 2026-07-29

CVE-2026-33267

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-29T08:16:30.983Z and has not been modified since then. The CVE-2026-33267 vulnerability is an Improper Input Validation issue in Apache Traffic Server, affecting versions from 9.2.0 through 9.2.14 and from 10.1.0 through 10.1.3. The vulnerability has a CVSS score of 7.7 and is classified as HIGH sev [truncated]

MEDIUM Apache CVE published 2026-07-29

CVE-2026-24033

The CVE-2026-24033 record describes an inconsistent interpretation of HTTP requests, also known as HTTP request/response smuggling, in Apache Traffic Server. This issue affects versions from 10.0.0 through 10.1.3 and from 9.0.0 through 9.2.14. The CVSS score is 6.9, indicating a medium severity vulnerability. Users of Apache Traffic Server should be aware of this vulnerability and take necessary actions t [truncated]

MEDIUM Apache CVE published 2026-07-28

CVE-2026-66299

Apache Tomcat has an Uncontrolled Resource Consumption vulnerability in its WebSocket chat example, affecting versions 11.0.0-M20 through 11.0.24, 10.1.24 through 10.1.57, and 9.0.89 through 9.0.120. Users who have removed the examples web application are not affected. The issue is fixed in versions 11.0.25, 10.1.58, and 9.0.121. This vulnerability can lead to resource exhaustion, posing a significant ris [truncated]

HIGH Apache CVE published 2026-07-24

CVE-2026-66143

Apache Neethi 3.2.2 has a vulnerability that allows bypassing the maximum number of normalized policy alternatives via crafted policies, potentially leading to a denial of service attack through resource consumption. This issue arises from the software's inability to properly handle certain policy configurations, which can be exploited to cause resource exhaustion. Users are advised to upgrade to version [truncated]

HIGH Apache CVE published 2026-07-24

CVE-2026-66142

Apache Neethi is vulnerable to uncontrolled recursion when parsing policies that lack policy Ids or with deeply nested structures. This issue may lead to a denial of service attack due to runtime memory exhaustion. Users are recommended to upgrade to version 3.2.3, which fixes this issue. The vulnerability arises from the way Apache Neethi handles policy parsing, which can lead to a denial of service attack.

MEDIUM Apache CVE published 2026-07-24

CVE-2026-46452

CVE-2026-46452 is an Improper Input Validation vulnerability in Apache NimBLE's Mesh Proxy SAR reassembly. This issue may result in passing broken data toward the application, leading to memory pressure and unstable parsing behavior. The vulnerability affects Apache NimBLE through version 1.9.0. Users are recommended to upgrade to version 1.10.0, which fixes the issue. This vulnerability has a CVSS score [truncated]

HIGH Apache CVE published 2026-07-24

CVE-2026-45816

CVE-2026-45816 is a NULL Pointer Dereference vulnerability in Apache NimBLE, specifically in the LE Long Term Key Request event. The vulnerability requires disabled asserts, which otherwise would trigger before the NULL dereference, and a bogus or misbehaving controller. Due to these conditions, the severity of the issue is considered low. The vulnerability affects Apache NimBLE through version 1.9.0. Use [truncated]

CRITICAL Apache CVE published 2026-07-21

CVE-2026-64606

A deserialization of untrusted data vulnerability exists in Apache Fory, potentially allowing class-registration checks to be bypassed during Java lambda deserialization. The issue affects Apache Fory versions before 1.4.0. Users are advised to upgrade to version 1.4.0, which fixes the issue. This vulnerability has a CVSS score of 9.8 and is considered CRITICAL. The vulnerability is related to the lambda [truncated]