Source: trafficserver
Version: 9.2.5+ds-1
Severity: grave
Tags: security upstream
Justification: user security hole
X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>

Hi,

The following vulnerabilities were published for trafficserver.

CVE-2026-22068[0]:
| Regular Expression without Anchors vulnerability in Apache Traffic
| Server.  This issue affects Apache Traffic Server: from 10.0.X
| through 10.1.3, from 9.0.X through 9.2.14.  Users are recommended to
| upgrade to version 9.2.15 or 10.1.4, which fixes the issue.


CVE-2026-24033[1]:
| Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response
| Smuggling') vulnerability in Apache Traffic Server.  This issue
| affects Apache Traffic Server: from 10.0.0 through 10.1.3, from
| 9.0.0 through 9.2.14.  Users are recommended to upgrade to version
| 9.2.15 or 10.1.4, which fixes the issue.


CVE-2026-33267[2]:
| Improper Input Validation vulnerability in Apache Traffic Server.
| This issue affects Apache Traffic Server: from 9.2.0 through 9.2.14,
| from 10.1.0 through 10.1.3.  Users are recommended to upgrade to
| version 9.2.15 or 10.1.4, which fixes the issue.


CVE-2026-33930[3]:
| Apache Traffic Server copies the client Host header into a fixed-
| size stack buffer without a bound during redirect handling, so an
| over-long Host header overflows the stack when redirect following is
| enabled.  This issue affects Apache Traffic Server: from 8.0.0
| through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through
| 10.1.3.  Users are recommended to upgrade to version 9.2.15 or
| 10.1.4, which fix the issue.


CVE-2026-41920[4]:
| Improper Access Control vulnerability in Apache Traffic Server.
| This issue affects Apache Traffic Server: from 9.0.0 through 9.1.14,
| from 10.0.0 through 10.1.3.  Users are recommended to upgrade to
| version 9.1.15 or 10.1.4, which fixes the issue.


CVE-2026-57834[5]:
| Apache Traffic Server allows request smuggling if chunked messages
| are malformed.  This issue affects Apache Traffic Server: from 8.0.0
| through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through
| 10.1.3.  Users are recommended to upgrade to version 9.2.15 or
| 10.1.4, which fix the issue.


CVE-2026-58150[6]:
| Apache Traffic Server does not reject Transfer-Encoding in HTTP/2
| requests, allowing downgrade request smuggling.  This issue affects
| Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through
| 9.2.14, from 10.0.0 through 10.1.3.  Users are recommended to
| upgrade to version 9.2.15 or 10.1.4, which fix the issue.


CVE-2026-58151[7]:
| Apache Traffic Server can be crashed or driven to resource
| exhaustion by abusive HTTP/2 framing and flow-control.  This issue
| affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0
| through 9.2.14, from 10.0.0 through 10.1.3.  Users are recommended
| to upgrade to version 9.2.15 or 10.1.4, which fix the issue.


CVE-2026-58152[8]:
| Apache Traffic Server mishandles integers while decoding HPACK/XPACK
| headers, corrupting memory.  This issue affects Apache Traffic
| Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from
| 10.0.0 through 10.1.3.  Users are recommended to upgrade to version
| 9.2.15 or 10.1.4, which fix the issue.


CVE-2026-58153[9]:
| Apache Traffic Server forwards HTTP/2 origin trailers to HTTP/1
| clients without proper chunked framing when converting HTTP/2 to
| HTTP/1.  This issue affects Apache Traffic Server: from 10.0.0
| through 10.1.3.  Users are recommended to upgrade to version 9.2.15
| or 10.1.4, which fix the issue.


CVE-2026-58154[10]:
| Apache Traffic Server can write out of bounds or overflow integers
| while parsing MIME and HTTP headers.  This issue affects Apache
| Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14,
| from 10.0.0 through 10.1.3.  Users are recommended to upgrade to
| version 9.2.15 or 10.1.4, which fix the issue.


CVE-2026-58155[11]:
| Apache Traffic Server truncates over-long header names, allowing
| header aliasing, request smuggling, and policy bypass.  This issue
| affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0
| through 9.2.14, from 10.0.0 through 10.1.3.  Users are recommended
| to upgrade to version 9.2.15 or 10.1.4, which fix the issue.


CVE-2026-58156[12]:
| Apache Traffic Server mis-parses ports in URLs and userinfo,
| allowing port-based access-control bypass.  This issue affects
| Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through
| 9.2.14, from 10.0.0 through 10.1.3.  Users are recommended to
| upgrade to version 9.2.15 or 10.1.4, which fix the issue.


CVE-2026-58157[13]:
| Apache Traffic Server can reuse server sessions and tunnels
| improperly, exposing data across client connections.  This issue
| affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0
| through 9.2.14, from 10.0.0 through 10.1.3.  Users are recommended
| to upgrade to version 9.2.15 or 10.1.4, which fix the issue.


CVE-2026-58158[14]:
| Apache Traffic Server mishandles PROXY protocol input, truncating
| ports and overflowing the stack.  This issue affects Apache Traffic
| Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from
| 10.0.0 through 10.1.3.  Users are recommended to upgrade to version
| 9.2.15 or 10.1.4, which fix the issue.


CVE-2026-58159[15]:
| Apache Traffic Server can bypass IP access controls on UDS listeners
| and through ACL matching errors.  This issue affects Apache Traffic
| Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from
| 10.0.0 through 10.1.3.  Users are recommended to upgrade to version
| 9.2.15 or 10.1.4, which fix the issue.


CVE-2026-58160[16]:
| Apache Traffic Server reads out of bounds while parsing DNS answers.
| This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9,
| from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3.  Users are
| recommended to upgrade to version 9.2.15 or 10.1.4, which fix the
| issue.


CVE-2026-58161[17]:
| Apache Traffic Server can crash from null dereferences and dangling
| references in TLS and SNI handling.  This issue affects Apache
| Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14,
| from 10.0.0 through 10.1.3.  Users are recommended to upgrade to
| version 9.2.15 or 10.1.4, which fix the issue.


CVE-2026-58162[18]:
| The Apache Traffic Server certifier plugin generates certificates
| based on attacker-controlled client SNI.  This issue affects Apache
| Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14,
| from 10.0.0 through 10.1.3.  Users are recommended to upgrade to
| version 9.2.15 or 10.1.4, which fix the issue.


CVE-2026-58163[19]:
| Apache Traffic Server mishandles on-disk cache fields and object
| lifetimes, corrupting state or crashing.  This issue affects Apache
| Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14,
| from 10.0.0 through 10.1.3.  Users are recommended to upgrade to
| version 9.2.15 or 10.1.4, which fix the issue.


CVE-2026-58164[20]:
| Apache Traffic Server has use-after-free and time-of-check/time-of-
| use errors in remap configuration handling.  This issue affects
| Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through
| 9.2.14, from 10.0.0 through 10.1.3.  Users are recommended to
| upgrade to version 9.2.15 or 10.1.4, which fix the issue.


CVE-2026-58175[21]:
| Apache Traffic Server leaks memory when handling HostDB SRV records.
| This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9,
| from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3.  Users are
| recommended to upgrade to version 9.2.15 or 10.1.4, which fix the
| issue.


CVE-2026-58177[22]:
| The Apache Traffic Server Cripts framework has out-of-bounds writes,
| path traversal, and use-after-free errors.  This issue affects
| Apache Traffic Server: from 10.0.0 through 10.1.3.  Users are
| recommended to upgrade to version 10.1.4, which fix the issue.


CVE-2026-58178[23]:
| The Apache Traffic Server ESI plugin can recurse without bound and
| fetch attacker-controlled URLs.  This issue affects Apache Traffic
| Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from
| 10.0.0 through 10.1.3.  Users are recommended to upgrade to version
| 9.2.15 or 10.1.4, which fix the issue.


CVE-2026-58179[24]:
| The Apache Traffic Server regex_remap plugin overflows the stack and
| integers from substitution input.  This issue affects Apache Traffic
| Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from
| 10.0.0 through 10.1.3.  Users are recommended to upgrade to version
| 9.2.15 or 10.1.4, which fix the issue.


CVE-2026-58180[25]:
| The Apache Traffic Server txn_box plugin overflows the stack from
| attacker-controlled input.  This issue affects Apache Traffic
| Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from
| 10.0.0 through 10.1.3.  Users are recommended to upgrade to version
| 9.2.15 or 10.1.4, which fix the issue.


CVE-2026-58181[26]:
| The Apache Traffic Server uri_signing and url_sig plugins can
| exhaust the stack or crash on attacker input.  This issue affects
| Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through
| 9.2.14, from 10.0.0 through 10.1.3.  Users are recommended to
| upgrade to version 9.2.15 or 10.1.4, which fix the issue.


CVE-2026-58182[27]:
| The Apache Traffic Server ts_lua plugin mishandles initialization,
| transform context, and per-instance state.  This issue affects
| Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through
| 9.2.14, from 10.0.0 through 10.1.3.  Users are recommended to
| upgrade to version 9.2.15 or 10.1.4, which fix the issue.


CVE-2026-58183[28]:
| The Apache Traffic Server prefetch plugin can crash when processing
| attacker-influenced input.  This issue affects Apache Traffic
| Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from
| 10.0.0 through 10.1.3.  Users are recommended to upgrade to version
| 9.2.15 or 10.1.4, which fix the issue.


CVE-2026-58184[29]:
| The Apache Traffic Server header_rewrite plugin can crash or corrupt
| memory during cookie operations and CIDR condition matching.  This
| issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from
| 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3.  Users are
| recommended to upgrade to version 9.2.15 or 10.1.4, which fix the
| issue.


CVE-2026-58185[30]:
| The Apache Traffic Server intercept plugin has a use-after-free.
| This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9,
| from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3.  Users are
| recommended to upgrade to version 9.2.15 or 10.1.4, which fix the
| issue.


CVE-2026-58186[31]:
| The Apache Traffic Server webp_transform plugin can decode unsafely
| and serve mislabeled, cacheable responses.  This issue affects
| Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through
| 9.2.14, from 10.0.0 through 10.1.3.  Users are recommended to
| upgrade to version 9.2.15 or 10.1.4, which fix the issue.


CVE-2026-58187[32]:
| The Apache Traffic Server multiplexer plugin overruns its chunk-
| decode buffer on upstream input, enabling denial of service.  This
| issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from
| 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3.  Users are
| recommended to upgrade to version 9.2.15 or 10.1.4, which fix the
| issue.


CVE-2026-58188[33]:
| Several Apache Traffic Server experimental plugins have memory-
| safety and limit-bypass errors.  This issue affects Apache Traffic
| Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from
| 10.0.0 through 10.1.3.  Users are recommended to upgrade to version
| 9.2.15 or 10.1.4, which fix the issue.


CVE-2026-58189[34]:
| Apache Traffic Server allows redirect-limit bypass when plugins
| reset the retry counter, enabling SSRF amplification.  This issue
| affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0
| through 9.2.14, from 10.0.0 through 10.1.3.  Users are recommended
| to upgrade to version 9.2.15 or 10.1.4, which fix the issue.


CVE-2026-65100[35]:
| Apache Traffic Server updates the HTTP/2 HPACK dynamic table before
| confirming the header block encoded successfully, so an encode
| failure leaves the encoder out of sync with the peer decoder and
| corrupts subsequent header blocks on the connection.  This issue
| affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0
| through 9.2.14, from 10.0.0 through 10.1.3.  Users are recommended
| to upgrade to version 9.2.15 or 10.1.4, which fix the issue.


CVE-2026-65324[36]:
| Apache Traffic Server drops the per-stream buffer cap when
| dechunking HTTP/2 or HTTP/3 responses, letting a slow client exhaust
| server memory.  This issue affects Apache Traffic Server: from 8.0.0
| through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through
| 10.1.3.  Users are recommended to upgrade to version 9.2.15 or
| 10.1.4, which fix the issue.


CVE-2026-65325[37]:
| Apache Traffic Server reuses multiplexed HTTP/2 origin connections
| without verifying the server certificate covers the new request
| hostname.  This issue affects Apache Traffic Server: from 9.0.0
| through 9.2.14, from 10.0.0 through 10.1.3.  Users are recommended
| to upgrade to version 9.2.15 or 10.1.4, which fix the issue.


If you fix the vulnerabilities please also make sure to include the
CVE (Common Vulnerabilities & Exposures) ids in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-22068
    https://www.cve.org/CVERecord?id=CVE-2026-22068
[1] https://security-tracker.debian.org/tracker/CVE-2026-24033
    https://www.cve.org/CVERecord?id=CVE-2026-24033
[2] https://security-tracker.debian.org/tracker/CVE-2026-33267
    https://www.cve.org/CVERecord?id=CVE-2026-33267
[3] https://security-tracker.debian.org/tracker/CVE-2026-33930
    https://www.cve.org/CVERecord?id=CVE-2026-33930
[4] https://security-tracker.debian.org/tracker/CVE-2026-41920
    https://www.cve.org/CVERecord?id=CVE-2026-41920
[5] https://security-tracker.debian.org/tracker/CVE-2026-57834
    https://www.cve.org/CVERecord?id=CVE-2026-57834
[6] https://security-tracker.debian.org/tracker/CVE-2026-58150
    https://www.cve.org/CVERecord?id=CVE-2026-58150
[7] https://security-tracker.debian.org/tracker/CVE-2026-58151
    https://www.cve.org/CVERecord?id=CVE-2026-58151
[8] https://security-tracker.debian.org/tracker/CVE-2026-58152
    https://www.cve.org/CVERecord?id=CVE-2026-58152
[9] https://security-tracker.debian.org/tracker/CVE-2026-58153
    https://www.cve.org/CVERecord?id=CVE-2026-58153
[10] https://security-tracker.debian.org/tracker/CVE-2026-58154
    https://www.cve.org/CVERecord?id=CVE-2026-58154
[11] https://security-tracker.debian.org/tracker/CVE-2026-58155
    https://www.cve.org/CVERecord?id=CVE-2026-58155
[12] https://security-tracker.debian.org/tracker/CVE-2026-58156
    https://www.cve.org/CVERecord?id=CVE-2026-58156
[13] https://security-tracker.debian.org/tracker/CVE-2026-58157
    https://www.cve.org/CVERecord?id=CVE-2026-58157
[14] https://security-tracker.debian.org/tracker/CVE-2026-58158
    https://www.cve.org/CVERecord?id=CVE-2026-58158
[15] https://security-tracker.debian.org/tracker/CVE-2026-58159
    https://www.cve.org/CVERecord?id=CVE-2026-58159
[16] https://security-tracker.debian.org/tracker/CVE-2026-58160
    https://www.cve.org/CVERecord?id=CVE-2026-58160
[17] https://security-tracker.debian.org/tracker/CVE-2026-58161
    https://www.cve.org/CVERecord?id=CVE-2026-58161
[18] https://security-tracker.debian.org/tracker/CVE-2026-58162
    https://www.cve.org/CVERecord?id=CVE-2026-58162
[19] https://security-tracker.debian.org/tracker/CVE-2026-58163
    https://www.cve.org/CVERecord?id=CVE-2026-58163
[20] https://security-tracker.debian.org/tracker/CVE-2026-58164
    https://www.cve.org/CVERecord?id=CVE-2026-58164
[21] https://security-tracker.debian.org/tracker/CVE-2026-58175
    https://www.cve.org/CVERecord?id=CVE-2026-58175
[22] https://security-tracker.debian.org/tracker/CVE-2026-58177
    https://www.cve.org/CVERecord?id=CVE-2026-58177
[23] https://security-tracker.debian.org/tracker/CVE-2026-58178
    https://www.cve.org/CVERecord?id=CVE-2026-58178
[24] https://security-tracker.debian.org/tracker/CVE-2026-58179
    https://www.cve.org/CVERecord?id=CVE-2026-58179
[25] https://security-tracker.debian.org/tracker/CVE-2026-58180
    https://www.cve.org/CVERecord?id=CVE-2026-58180
[26] https://security-tracker.debian.org/tracker/CVE-2026-58181
    https://www.cve.org/CVERecord?id=CVE-2026-58181
[27] https://security-tracker.debian.org/tracker/CVE-2026-58182
    https://www.cve.org/CVERecord?id=CVE-2026-58182
[28] https://security-tracker.debian.org/tracker/CVE-2026-58183
    https://www.cve.org/CVERecord?id=CVE-2026-58183
[29] https://security-tracker.debian.org/tracker/CVE-2026-58184
    https://www.cve.org/CVERecord?id=CVE-2026-58184
[30] https://security-tracker.debian.org/tracker/CVE-2026-58185
    https://www.cve.org/CVERecord?id=CVE-2026-58185
[31] https://security-tracker.debian.org/tracker/CVE-2026-58186
    https://www.cve.org/CVERecord?id=CVE-2026-58186
[32] https://security-tracker.debian.org/tracker/CVE-2026-58187
    https://www.cve.org/CVERecord?id=CVE-2026-58187
[33] https://security-tracker.debian.org/tracker/CVE-2026-58188
    https://www.cve.org/CVERecord?id=CVE-2026-58188
[34] https://security-tracker.debian.org/tracker/CVE-2026-58189
    https://www.cve.org/CVERecord?id=CVE-2026-58189
[35] https://security-tracker.debian.org/tracker/CVE-2026-65100
    https://www.cve.org/CVERecord?id=CVE-2026-65100
[36] https://security-tracker.debian.org/tracker/CVE-2026-65324
    https://www.cve.org/CVERecord?id=CVE-2026-65324
[37] https://security-tracker.debian.org/tracker/CVE-2026-65325
    https://www.cve.org/CVERecord?id=CVE-2026-65325

Regards,
Salvatore

Reply via email to