Bug#1143062: trafficserver: CVE-2026-22068 CVE-2026-24033 CVE-2026-33267 CVE-2026-33930 CVE-2026-41920 CVE-2026-57834 CVE-2026-58150 CVE-2026-58151 CVE-2026-58152 CVE-2026-58153 CVE-2026-58154 CVE-2026-58155 CVE-2026-58156 CVE-2026-58157 CVE-2026-58158 CVE-2026-58159 CVE-2026-58160 CVE-2026-58161 CVE-2026-58162 CVE-2026-58163 CVE-2026-58164 CVE-2026-58175 CVE-2026-58177 CVE-2026-58178 CVE-2026-58179 CVE-2026-58180 CVE-2026-58181 CVE-2026-58182 CVE-2026-58183 CVE-2026-58184 CVE-2026-58185 CVE-2026-58186 CVE-2026-58187 CVE-2026-58188 CVE-2026-58189 CVE-2026-65100 CVE-2026-65324 CVE-2026-65325

Salvatore Bonaccorso <[email protected]>
Newsgroups gmane.linux.debian.devel.bugs.rc
Message-ID <[email protected]>
Source: trafficserver
Version: 9.2.5+ds-1
Severity: grave
Tags: security upstream
Justification: user security hole
X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>

Hi,

The following vulnerabilities were published for trafficserver.

CVE-2026-22068[0]:
| Regular Expression without Anchors vulnerability in Apache Traffic
| Server.  This issue affects Apache Traffic Server: from 10.0.X
| through 10.1.3, from 9.0.X through 9.2.14.  Users are recommended to
| upgrade to version 9.2.15 or 10.1.4, which fixes the issue.


CVE-2026-24033[1]:
| Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response
| Smuggling') vulnerability in Apache Traffic Server.  This issue
| affects Apache Traffic Server: from 10.0.0 through 10.1.3, from
| 9.0.0 through 9.2.14.  Users are recommended to upgrade to version
| 9.2.15 or 10.1.4, which fixes the issue.


CVE-2026-33267[2]:
| Improper Input Validation vulnerability in Apache Traffic Server.
| This issue affects Apache Traffic Server: from 9.2.0 through 9.2.14,
| from 10.1.0 through 10.1.3.  Users are recommended to upgrade to
| version 9.2.15 or 10.1.4, which fixes the issue.


CVE-2026-33930[3]:
| Apache Traffic Server copies the client Host header into a fixed-
| size stack buffer without a bound during redirect handling, so an
| over-long Host header overflows the stack when redirect following is
| enabled.  This issue affects Apache Traffic Server: from 8.0.0
| through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through
| 10.1.3.  Users are recommended to upgrade to version 9.2.15 or
| 10.1.4, which fix the issue.


CVE-2026-41920[4]:
| Improper Access Control vulnerability in Apache Traffic Server.
| This issue affects Apache Traffic Server: from 9.0.0 through 9.1.14,
| from 10.0.0 through 10.1.3.  Users are recommended to upgrade to
| version 9.1.15 or 10.1.4, which fixes the issue.


CVE-2026-57834[5]:
| Apache Traffic Server allows request smuggling if chunked messages
| are malformed.  This issue affects Apache Traffic Server: from 8.0.0
| through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through
| 10.1.3.  Users are recommended to upgrade to version 9.2.15 or
| 10.1.4, which fix the issue.


CVE-2026-58150[6]:
| Apache Traffic Server does not reject Transfer-Encoding in HTTP/2
| requests, allowing downgrade request smuggling.  This issue affects
| Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through
| 9.2.14, from 10.0.0 through 10.1.3.  Users are recommended to
| upgrade to version 9.2.15 or 10.1.4, which fix the issue.


CVE-2026-58151[7]:
| Apache Traffic Server can be crashed or driven to resource
| exhaustion by abusive HTTP/2 framing and flow-control.  This issue
| affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0
| through 9.2.14, from 10.0.0 through 10.1.3.  Users are recommended
| to upgrade to version 9.2.15 or 10.1.4, which fix the issue.


CVE-2026-58152[8]:
| Apache Traffic Server mishandles integers while decoding HPACK/XPACK
| headers, corrupting memory.  This issue affects Apache Traffic
| Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from
| 10.0.0 through 10.1.3.  Users are recommended to upgrade to version
| 9.2.15 or 10.1.4, which fix the issue.


CVE-2026-58153[9]:
| Apache Traffic Server forwards HTTP/2 origin trailers to HTTP/1
| clients without proper chunked framing when converting HTTP/2 to
| HTTP/1.  This issue affects Apache Traffic Server: from 10.0.0
| through 10.1.3.  Users are recommended to upgrade to version 9.2.15
| or 10.1.4, which fix the issue.


CVE-2026-58154[10]:
| Apache Traffic Server can write out of bounds or overflow integers
| while parsing MIME and HTTP headers.  This issue affects Apache
| Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14,
| from 10.0.0 through 10.1.3.  Users are recommended to upgrade to
| version 9.2.15 or 10.1.4, which fix the issue.


CVE-2026-58155[11]:
| Apache Traffic Server truncates over-long header names, allowing
| header aliasing, request smuggling, and policy bypass.  This issue
| affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0
| through 9.2.14, from 10.0.0 through 10.1.3.  Users are recommended
| to upgrade to version 9.2.15 or 10.1.4, which fix the issue.


CVE-2026-58156[12]:
| Apache Traffic Server mis-parses ports in URLs and userinfo,
| allowing port-based access-control bypass.  This issue affects
| Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through
| 9.2.14, from 10.0.0 through 10.1.3.  Users are recommended to
| upgrade to version 9.2.15 or 10.1.4, which fix the issue.


CVE-2026-58157[13]:
| Apache Traffic Server can reuse server sessions and tunnels
| improperly, exposing data across client connections.  This issue
| affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0
| through 9.2.14, from 10.0.0 through 10.1.3.  Users are recommended
| to upgrade to version 9.2.15 or 10.1.4, which fix the issue.


CVE-2026-58158[14]:
| Apache Traffic Server mishandles PROXY protocol input, truncating
| ports and overflowing the stack.  This issue affects Apache Traffic
| Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from
| 10.0.0 through 10.1.3.  Users are recommended to upgrade to version
| 9.2.15 or 10.1.4, which fix the issue.


CVE-2026-58159[15]:
| Apache Traffic Server can bypass IP access controls on UDS listeners
| and through ACL matching errors.  This issue affects Apache Traffic
| Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from
| 10.0.0 through 10.1.3.  Users are recommended to upgrade to version
| 9.2.15 or 10.1.4, which fix the issue.


CVE-2026-58160[16]:
| Apache Traffic Server reads out of bounds while parsing DNS answers.
| This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9,
| from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3.  Users are
| recommended to upgrade to version 9.2.15 or 10.1.4, which fix the
| issue.


CVE-2026-58161[17]:
| Apache Traffic Server can crash from null dereferences and dangling
| references in TLS and SNI handling.  This issue affects Apache
| Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14,
| from 10.0.0 through 10.1.3.  Users are recommended to upgrade to
| version 9.2.15 or 10.1.4, which fix the issue.


CVE-2026-58162[18]:
| The Apache Traffic Server certifier plugin generates certificates
| based on attacker-controlled client SNI.  This issue affects Apache
| Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14,
| from 10.0.0 through 10.1.3.  Users are recommended to upgrade to
| version 9.2.15 or 10.1.4, which fix the issue.


CVE-2026-58163[19]:
| Apache Traffic Server mishandles on-disk cache fields and object
| lifetimes, corrupting state or crashing.  This issue affects Apache
| Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14,
| from 10.0.0 through 10.1.3.  Users are recommended to upgrade to
| version 9.2.15 or 10.1.4, which fix the issue.


CVE-2026-58164[20]:
| Apache Traffic Server has use-after-free and time-of-check/time-of-
| use errors in remap configuration handling.  This issue affects
| Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through
| 9.2.14, from 10.0.0 through 10.1.3.  Users are recommended to
| upgrade to version 9.2.15 or 10.1.4, which fix the issue.


CVE-2026-58175[21]:
| Apache Traffic Server leaks memory when handling HostDB SRV records.
| This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9,
| from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3.  Users are
| recommended to upgrade to version 9.2.15 or 10.1.4, which fix the
| issue.


CVE-2026-58177[22]:
| The Apache Traffic Server Cripts framework has out-of-bounds writes,
| path traversal, and use-after-free errors.  This issue affects
| Apache Traffic Server: from 10.0.0 through 10.1.3.  Users are
| recommended to upgrade to version 10.1.4, which fix the issue.


CVE-2026-58178[23]:
| The Apache Traffic Server ESI plugin can recurse without bound and
| fetch attacker-controlled URLs.  This issue affects Apache Traffic
| Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from
| 10.0.0 through 10.1.3.  Users are recommended to upgrade to version
| 9.2.15 or 10.1.4, which fix the issue.


CVE-2026-58179[24]:
| The Apache Traffic Server regex_remap plugin overflows the stack and
| integers from substitution input.  This issue affects Apache Traffic
| Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from
| 10.0.0 through 10.1.3.  Users are recommended to upgrade to version
| 9.2.15 or 10.1.4, which fix the issue.


CVE-2026-58180[25]:
| The Apache Traffic Server txn_box plugin overflows the stack from
| attacker-controlled input.  This issue affects Apache Traffic
| Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from
| 10.0.0 through 10.1.3.  Users are recommended to upgrade to version
| 9.2.15 or 10.1.4, which fix the issue.


CVE-2026-58181[26]:
| The Apache Traffic Server uri_signing and url_sig plugins can
| exhaust the stack or crash on attacker input.  This issue affects
| Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through
| 9.2.14, from 10.0.0 through 10.1.3.  Users are recommended to
| upgrade to version 9.2.15 or 10.1.4, which fix the issue.


CVE-2026-58182[27]:
| The Apache Traffic Server ts_lua plugin mishandles initialization,
| transform context, and per-instance state.  This issue affects
| Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through
| 9.2.14, from 10.0.0 through 10.1.3.  Users are recommended to
| upgrade to version 9.2.15 or 10.1.4, which fix the issue.


CVE-2026-58183[28]:
| The Apache Traffic Server prefetch plugin can crash when processing
| attacker-influenced input.  This issue affects Apache Traffic
| Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from
| 10.0.0 through 10.1.3.  Users are recommended to upgrade to version
| 9.2.15 or 10.1.4, which fix the issue.


CVE-2026-58184[29]:
| The Apache Traffic Server header_rewrite plugin can crash or corrupt
| memory during cookie operations and CIDR condition matching.  This
| issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from
| 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3.  Users are
| recommended to upgrade to version 9.2.15 or 10.1.4, which fix the
| issue.


CVE-2026-58185[30]:
| The Apache Traffic Server intercept plugin has a use-after-free.
| This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9,
| from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3.  Users are
| recommended to upgrade to version 9.2.15 or 10.1.4, which fix the
| issue.


CVE-2026-58186[31]:
| The Apache Traffic Server webp_transform plugin can decode unsafely
| and serve mislabeled, cacheable responses.  This issue affects
| Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through
| 9.2.14, from 10.0.0 through 10.1.3.  Users are recommended to
| upgrade to version 9.2.15 or 10.1.4, which fix the issue.


CVE-2026-58187[32]:
| The Apache Traffic Server multiplexer plugin overruns its chunk-
| decode buffer on upstream input, enabling denial of service.  This
| issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from
| 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3.  Users are
| recommended to upgrade to version 9.2.15 or 10.1.4, which fix the
| issue.


CVE-2026-58188[33]:
| Several Apache Traffic Server experimental plugins have memory-
| safety and limit-bypass errors.  This issue affects Apache Traffic
| Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from
| 10.0.0 through 10.1.3.  Users are recommended to upgrade to version
| 9.2.15 or 10.1.4, which fix the issue.


CVE-2026-58189[34]:
| Apache Traffic Server allows redirect-limit bypass when plugins
| reset the retry counter, enabling SSRF amplification.  This issue
| affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0
| through 9.2.14, from 10.0.0 through 10.1.3.  Users are recommended
| to upgrade to version 9.2.15 or 10.1.4, which fix the issue.


CVE-2026-65100[35]:
| Apache Traffic Server updates the HTTP/2 HPACK dynamic table before
| confirming the header block encoded successfully, so an encode
| failure leaves the encoder out of sync with the peer decoder and
| corrupts subsequent header blocks on the connection.  This issue
| affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0
| through 9.2.14, from 10.0.0 through 10.1.3.  Users are recommended
| to upgrade to version 9.2.15 or 10.1.4, which fix the issue.


CVE-2026-65324[36]:
| Apache Traffic Server drops the per-stream buffer cap when
| dechunking HTTP/2 or HTTP/3 responses, letting a slow client exhaust
| server memory.  This issue affects Apache Traffic Server: from 8.0.0
| through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through
| 10.1.3.  Users are recommended to upgrade to version 9.2.15 or
| 10.1.4, which fix the issue.


CVE-2026-65325[37]:
| Apache Traffic Server reuses multiplexed HTTP/2 origin connections
| without verifying the server certificate covers the new request
| hostname.  This issue affects Apache Traffic Server: from 9.0.0
| through 9.2.14, from 10.0.0 through 10.1.3.  Users are recommended
| to upgrade to version 9.2.15 or 10.1.4, which fix the issue.


If you fix the vulnerabilities please also make sure to include the
CVE (Common Vulnerabilities & Exposures) ids in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-22068
    https://www.cve.org/CVERecord?id=CVE-2026-22068
[1] https://security-tracker.debian.org/tracker/CVE-2026-24033
    https://www.cve.org/CVERecord?id=CVE-2026-24033
[2] https://security-tracker.debian.org/tracker/CVE-2026-33267
    https://www.cve.org/CVERecord?id=CVE-2026-33267
[3] https://security-tracker.debian.org/tracker/CVE-2026-33930
    https://www.cve.org/CVERecord?id=CVE-2026-33930
[4] https://security-tracker.debian.org/tracker/CVE-2026-41920
    https://www.cve.org/CVERecord?id=CVE-2026-41920
[5] https://security-tracker.debian.org/tracker/CVE-2026-57834
    https://www.cve.org/CVERecord?id=CVE-2026-57834
[6] https://security-tracker.debian.org/tracker/CVE-2026-58150
    https://www.cve.org/CVERecord?id=CVE-2026-58150
[7] https://security-tracker.debian.org/tracker/CVE-2026-58151
    https://www.cve.org/CVERecord?id=CVE-2026-58151
[8] https://security-tracker.debian.org/tracker/CVE-2026-58152
    https://www.cve.org/CVERecord?id=CVE-2026-58152
[9] https://security-tracker.debian.org/tracker/CVE-2026-58153
    https://www.cve.org/CVERecord?id=CVE-2026-58153
[10] https://security-tracker.debian.org/tracker/CVE-2026-58154
    https://www.cve.org/CVERecord?id=CVE-2026-58154
[11] https://security-tracker.debian.org/tracker/CVE-2026-58155
    https://www.cve.org/CVERecord?id=CVE-2026-58155
[12] https://security-tracker.debian.org/tracker/CVE-2026-58156
    https://www.cve.org/CVERecord?id=CVE-2026-58156
[13] https://security-tracker.debian.org/tracker/CVE-2026-58157
    https://www.cve.org/CVERecord?id=CVE-2026-58157
[14] https://security-tracker.debian.org/tracker/CVE-2026-58158
    https://www.cve.org/CVERecord?id=CVE-2026-58158
[15] https://security-tracker.debian.org/tracker/CVE-2026-58159
    https://www.cve.org/CVERecord?id=CVE-2026-58159
[16] https://security-tracker.debian.org/tracker/CVE-2026-58160
    https://www.cve.org/CVERecord?id=CVE-2026-58160
[17] https://security-tracker.debian.org/tracker/CVE-2026-58161
    https://www.cve.org/CVERecord?id=CVE-2026-58161
[18] https://security-tracker.debian.org/tracker/CVE-2026-58162
    https://www.cve.org/CVERecord?id=CVE-2026-58162
[19] https://security-tracker.debian.org/tracker/CVE-2026-58163
    https://www.cve.org/CVERecord?id=CVE-2026-58163
[20] https://security-tracker.debian.org/tracker/CVE-2026-58164
    https://www.cve.org/CVERecord?id=CVE-2026-58164
[21] https://security-tracker.debian.org/tracker/CVE-2026-58175
    https://www.cve.org/CVERecord?id=CVE-2026-58175
[22] https://security-tracker.debian.org/tracker/CVE-2026-58177
    https://www.cve.org/CVERecord?id=CVE-2026-58177
[23] https://security-tracker.debian.org/tracker/CVE-2026-58178
    https://www.cve.org/CVERecord?id=CVE-2026-58178
[24] https://security-tracker.debian.org/tracker/CVE-2026-58179
    https://www.cve.org/CVERecord?id=CVE-2026-58179
[25] https://security-tracker.debian.org/tracker/CVE-2026-58180
    https://www.cve.org/CVERecord?id=CVE-2026-58180
[26] https://security-tracker.debian.org/tracker/CVE-2026-58181
    https://www.cve.org/CVERecord?id=CVE-2026-58181
[27] https://security-tracker.debian.org/tracker/CVE-2026-58182
    https://www.cve.org/CVERecord?id=CVE-2026-58182
[28] https://security-tracker.debian.org/tracker/CVE-2026-58183
    https://www.cve.org/CVERecord?id=CVE-2026-58183
[29] https://security-tracker.debian.org/tracker/CVE-2026-58184
    https://www.cve.org/CVERecord?id=CVE-2026-58184
[30] https://security-tracker.debian.org/tracker/CVE-2026-58185
    https://www.cve.org/CVERecord?id=CVE-2026-58185
[31] https://security-tracker.debian.org/tracker/CVE-2026-58186
    https://www.cve.org/CVERecord?id=CVE-2026-58186
[32] https://security-tracker.debian.org/tracker/CVE-2026-58187
    https://www.cve.org/CVERecord?id=CVE-2026-58187
[33] https://security-tracker.debian.org/tracker/CVE-2026-58188
    https://www.cve.org/CVERecord?id=CVE-2026-58188
[34] https://security-tracker.debian.org/tracker/CVE-2026-58189
    https://www.cve.org/CVERecord?id=CVE-2026-58189
[35] https://security-tracker.debian.org/tracker/CVE-2026-65100
    https://www.cve.org/CVERecord?id=CVE-2026-65100
[36] https://security-tracker.debian.org/tracker/CVE-2026-65324
    https://www.cve.org/CVERecord?id=CVE-2026-65324
[37] https://security-tracker.debian.org/tracker/CVE-2026-65325
    https://www.cve.org/CVERecord?id=CVE-2026-65325

Regards,
Salvatore
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.